# IP Intelligence Briefing: 91.228.33.38/32
Classification: Moderate Risk
Date: Current Analysis
Scope: Full Profile Assessment
---
## Executive Summary
IP address 91.228.33.38 presents a moderate risk profile (55/100) with multiple DNSBL listings and elevated neighborhood abuse density. The IP is associated with the Polish hosting infrastructure provider Vatus (ASN 56838) and shows route instability. While no direct threat indicators or known campaigns are detected, the IP's presence on three DNSBL lists warrants monitoring.
---
## Network Identity
| Field | Value |
|---|---|
| **ASN** | 56838 (Vatus) |
| **Organization** | MNT-INSITE-SPZOO |
| **CIDR Block** | 91.228.32.0/22 |
| **RIR** | RIPE |
| **Country** | Poland (PL) |
| **Registration** | 2011-05-24 (5,540 days) |
| **BGP Path** | 3303 → 20804 → 56838 |
---
## Risk Assessment
Overall Score: 55/100 (Moderate Risk)
Threat Indicators:
- DNSBL Listings: 3 of 8 total lists
- Abuse Confidence: Not applicable (no active indicators)
- Known Campaigns: None detected
- Tor Exit/Proxy/VPN: Negative
Network Classification:
- Service Purpose: Firewalled / No Services
- No open ports detected
- No DNS resolution
- No HTTP services observed
- Not classified as CDN, hosting, VPN, or cloud infrastructure
---
## Neighborhood Analysis
Subnet: 91.228.33.0/24
Total Siblings: 63 IPs
Abuse Density: 11.1% (0.111)
Risk Distribution:
- High Risk: 7 IPs
- Medium Risk: 51 IPs
- Low Risk: 5 IPs
Notable Neighbors:
- 91.228.33.5 (Risk: 70)
- 91.228.33.7 (Risk: 80)
- 91.228.33.13 (Risk: 55)
- 91.228.33.17 (Risk: 55)
- 91.228.33.20 (Risk: 70)
---
## Historical Observations
Total Observations: 15
Key Historical Signals:
- Recent DNSBL listings detected (3 of 8 lists, max severity: high)
- ASN information stable (allocated 2011-05-24, RIPE registry)
- Prefix 91.228.32.0/22: 1 route change in 30 days
- Route stability: False
Temporal Behavior:
- Ownership changes: 0
- Threat observation count: 0
- Persistently malicious: No
---
## Technical Indicators
Geolocation:
- Region: Łódź Voivodeship
- City: Rozprza
- Coordinates: 51.92, 19.15
- Note: GeoPlausible validation failed
Control Plane:
- Origin ASN: 56838
- BGP Prefix: 91.228.32.0/22
- Route changes (30d): 1
- isRouteStable: False
- RPKI State: Not verified
Connectivity:
- Traceroute: 12 hops, 2 timeouts
- Transit Networks: Comcast
- Average RTT: ~62ms (mid-hop)
---
## Recommended Actions
Immediate (High Severity)
1. Increase Logging Verbosity: Monitor all activity from this IP address.
2. Implement Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 91.228.33.38 -j DROP
# nftables
nft add rule inet filter input ip saddr 91.228.33.38 drop
# nginx
deny 91.228.33.38;
```
3. WAF Integration:
- Cloudflare WAF: Block with expression `ip.src eq 91.228.33.38`
- AWS WAF: Add 91.228.33.38/32 to blocked IP set
Ongoing Monitoring
- Track route stability changes (currently unstable)
- Monitor neighborhood 91.228.33.0/24 for correlated malicious activity
- Review DNSBL listing status and severity
---
## Intelligence Conclusion
IP 91.228.33.38 is a Polish infrastructure address with moderate risk characteristics. The 11.1% abuse density in its /24 subnet and presence on three DNSBL lists indicate potential misuse, though no direct attack activity or known campaigns are currently associated with this IP. The route instability (1 change in 30 days) suggests network configuration changes that may affect traffic patterns.
Recommended Response: Implement defensive blocking per firewall rules provided, maintain elevated logging for 7-14 days, and monitor for any service emergence or behavioral changes. Correlate with neighborhood analysis for 91.228.33.0/24 when possible.
---
*Intelligence generated by IPDebrief. All data sourced from real-time network observations.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | MNT-INSITE-SPZOO |
| ASN | AS56838 |
| Network Name | Vatus |
| CIDR Block | 91.228.32.0/22 |
| RIR | RIPE |
| Country | PL |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS56838 |
| Network Prefix | 91.228.32.0/22 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 35% | 2 | 2 |
| Overall | 10% | 3 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-05 23:59:02 UTC |
| Last Seen | 2026-08-27 04:55:45 UTC |
| Profile Built | 2026-08-29 05:52:45 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 21 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 91.228.33.38
Who owns the IP address 91.228.33.38?
91.228.33.38 is registered to MNT-INSITE-SPZOO. The address falls within the 91.228.32.0/22 network block. Registration is held at RIPE.
Where is 91.228.33.38 located?
Geolocation data places 91.228.33.38 in Rozprza, Łódź Voivodeship, Poland. The local time zone is Europe/Warsaw. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 91.228.33.38 malicious or safe?
91.228.33.38 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.