# THREAT INTELLIGENCE BRIEFING
Target IP: 91.224.92.33/32
Date: 2026-07-24
Classification: Defensive Network Intelligence
---
## Executive Summary
IP address 91.224.92.33 presents as a low-risk infrastructure endpoint associated with the SERVEROFFER_LT network (ASN 209605). While the IP itself shows minimal threat indicators, the surrounding /24 subnet demonstrates elevated abuse density (11.8%), with multiple neighbors exhibiting high-risk profiles.
---
## Ownership and Infrastructure Profile
Network Registration:
- ASN: 209605 (BSTLT-MNT)
- Organization: SERVEROFFER_LT
- RIR: RIPE
- CIDR Block: 91.224.92.0/24
- Geolocation: United Kingdom (GB)
- Timezone: Europe/London
DNS Configuration:
- PTR Hostname: srv-91-224-92-33.serveroffer.net
- Forward Resolution: srv-91-224-92-33.serveroffer.net
- DNSSEC: Valid
- Email Authentication: No SPF/DMARC records detected
---
## Risk Assessment
Current Risk Score: 15 (Low Risk)
- Provider Score: 0
- Authority Score: 0
Threat Indicators:
- Blacklist Count: 0
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Is Cloud/CDN/VPN/Proxy: No
Network Classification:
- Service Purpose: Firewalled / No Services
- Open Ports: None detected
- TLS Certificate: None
- HTTP Banner: None
---
## Control Plane and Route Stability
- BGP Origin ASN: 209605
- AS Path: 3303 209605
- Route Stability: Unstable (1 change in last 30 days)
- DNSBL Listed: 1 of 8 total lists
- RPKI State: Not evaluated
- Route Changes (30d): 1
---
## Observation History
Signal Count: 19 observations
- Recent Activity: Observations recorded on 2026-07-24
- ASN Status: Allocated (2752 days old, registered 2019-01-10)
- Ownership Changes: 0
- Threat Persistence: 0 days
- Persistent Malicious Activity: No
---
## Neighborhood Analysis
Subnet: 91.224.92.0/24
- Total Siblings: 17 (excluding target)
- Abuse Density: 0.118 (11.8%)
- Risk Distribution: 2 High, 11 Medium, 4 Low
High-Risk Neighbors (Risk Score ≥ 65):
| IP Address | Risk Score | Authority Score |
|---|---|---|
| 91.224.92.159 | 80 | 50 |
| 91.224.92.190 | 80 | 50 |
| 91.224.92.78 | 65 | 50 |
| 91.224.92.127 | 65 | 50 |
---
## Relationships
Identified Associations:
1. Same Network: SERVEROFFER_LT (network-level association)
2. DNS Association: srv-91-224-92-33.serveroffer.net (reverse DNS)
---
## Recommended Actions
Current Status: No immediate security actions required.
Defensive Recommendations:
1. Monitor Subnet Abuse: The /24 subnet shows 11.8% abuse density. Consider implementing egress filtering for traffic to/from 91.224.92.0/24.
2. Route Stability Alert: The BGP route shows instability (1 change in 30 days). Monitor for potential route hijacking attempts.
3. DNSBL Monitoring: IP is listed on 1 of 8 DNSBLs. Investigate the listing source and consider blacklisting if confirmed malicious.
4. Neighbor Correlation: High-risk neighbors (91.224.92.159, 91.224.92.190, 91.224.92.78, 91.224.92.127) warrant correlation with any inbound/outbound traffic logs.
---
## Conclusion
IP 91.224.92.33 is a low-risk infrastructure endpoint with no active threat indicators. The primary concern is the elevated abuse density within the parent /24 subnet. SOC analysts should correlate traffic patterns with the four identified high-risk neighbors and monitor BGP route changes for potential network instability.
Threat Level: LOW
Priority: ROUTINE MONITORING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | BSTLT-MNT |
| ASN | AS209605 |
| Network Name | SERVEROFFER_LT |
| CIDR Block | 91.224.92.0/24 |
| RIR | RIPE |
| Country | LT |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | srv-91-224-92-33.serveroffer.net |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | srv-91-224-92-33.serveroffer.net |
🔐 DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS209605 |
| Network Prefix | 91.224.92.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 35% | 2 | 2 |
| Overall | 22% | 6 | 7 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-05 23:59:02 UTC |
| Last Seen | 2026-08-27 08:35:55 UTC |
| Profile Built | 2026-08-29 05:00:14 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 91.224.92.33
Who owns the IP address 91.224.92.33?
91.224.92.33 is registered to BSTLT-MNT. The address falls within the 91.224.92.0/24 network block. Registration is held at RIPE.
Where is 91.224.92.33 located?
Geolocation data places 91.224.92.33 in United Kingdom. The local time zone is Europe/London. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 91.224.92.33 malicious or safe?
91.224.92.33 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 91.224.92.33?
The reverse DNS (PTR) record for 91.224.92.33 is srv-91-224-92-33.serveroffer.net. This hostname is not forward-confirmed, so it should be treated as a weak signal.