# INTELLIGENCE BRIEFING: 91.224.237.52/32
Classification: Moderate Risk
Report Date: Current
Primary Location: Krotoszyn, Poland (PL)
ASN: AS197833 (ZAPNET-Karol-Zapart)
---
## EXECUTIVE SUMMARY
IP address 91.224.237.52 presents a moderate risk profile (65/100) associated with a small residential ISP in Poland. The IP operates as a single-service host with SSH enabled, is listed on 3 of 8 DNS blacklists, and shows route instability. The subnet exhibits low abuse density, though two neighboring IPs demonstrate elevated risk scores. No active threat campaigns or known attacker indicators were identified.
---
## OWNERSHIP AND INFRASTRUCTURE
- Organization: mnt-pl-zapnet-1 (slawomir zapart trading as zapnet karol zapart sp.j.)
- Network: 91.224.236.0/23
- Registration: RIR: RIPE
- DNS PTR: 91-224-237-52.zapnet-isp.net
- Service Profile: Single-Service Host
---
## THREAT INDICATORS
- Risk Score: 65/100
- DNSBL Listings: 3/8 total lists
- Route Stability: Unstable (isRouteStable: false)
- Operator Score: 0.2609 (Basic)
- Campaign Association: None detected
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
---
## NETWORK NEIGHBORHOOD ANALYSIS
Subnet: 91.224.237.52/24
- Abuse Density: 0 (clean classification)
- Total Siblings: 3
- Active Siblings: 2
- Threat Siblings: 0
Notable Neighbors:
- 91.224.237.93 (Risk: 65, Authority: 60)
- 91.224.237.152 (Risk: 55, Authority: 60)
---
## OBSERVATION HISTORY
Analysis of 20 signal observations reveals:
- Recent geolocation signals from July 31, 2026 confirming Poland (Krotoszyn)
- Trace completion: 13 hops to target reached
- Subnet classification consistently clean during observation window
- No persistent malicious threat patterns detected
- Ownership changes: 0
---
## NETWORK SERVICES
- Port 22/TCP: SSH (dropbear_2016.74)
- TLS Certificate: None
- HTTP: Not detected
- Email Auth: SPF/DMARC not configured
---
## RECOMMENDED ACTIONS
Priority: HIGH โ Increase logging verbosity and review recent activity from this IP.
Firewall Rules:
- iptables: `iptables -A INPUT -s 91.224.237.52 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 91.224.237.52 drop`
- nginx: `deny 91.224.237.52;`
- pfSense: `91.224.237.52/32`
- Cloudflare WAF: Block with expression `ip.src eq 91.224.237.52`
- AWS WAF: Add to whitelist with description "IPDebrief risk 65"
---
## ANALYST NOTES
The elevated risk score (65) combined with DNSBL listings and route instability warrants monitoring. While the subnet shows low abuse density and no immediate threat indicators, the IP's operational status as a single-service host with SSH exposure presents potential attack surface considerations. Recommended to maintain logging and evaluate against organizational threat tolerances before implementing blocking rules.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | mnt-pl-zapnet-1 |
| ASN | AS197833 |
| Network Name | ZAPNET-Karol-Zapart |
| CIDR Block | 91.224.236.0/23 |
| RIR | RIPE |
| Country | PL |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 91-224-237-52.zapnet-isp.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | 91-224-237-52.zapnet-isp.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-dropbear_2016.74 ,?9?OQk `?v???\[??curve25519-sha256@libssh.org,ecdh-sha2-nistp521,ecdh-sha |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 20% | 5 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-30 23:21:07 UTC |
| Last Seen | 2026-08-01 16:33:58 UTC |
| Profile Built | 2026-07-31 05:27:41 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 21 |
Full dossier details are available via our API.