# IP Intelligence Briefing: 91.234.137.214/32
Classification: High Risk | Date: Current | Severity: Elevated
## Executive Summary
IP address 91.234.137.214 presents a high-risk security profile (risk score: 80) associated with Ukraine. The IP operates a web server infrastructure within the LANPRO-NET network (ASN: 197218, registered to PP Dmutrashko Evgeny Vitalievich). While direct threat indicators are absent, the IP's risk profile is elevated, and the associated /24 subnet exhibits moderate abuse density with three confirmed threat siblings.
## Technical Profile
Ownership & Registration:
- ASN: 197218 (LANPRO-NET)
- Organization: PP Dmutrashko Evgeny Vitalievich
- Netname: LANPRO-NET
- CIDR Block: 91.234.136.0/22
- RIR: RIPE
- Country: Ukraine (UA)
- City: Glubokaya
Network Role & Services:
- Purpose: Web Server
- Open Ports: TCP/80 (HTTP), TCP/443 (HTTPS)
- Server Software: lighttpd/1.4.39
- DNSSEC: Valid
- Route Stability: False (potential BGP instability)
## Threat Assessment
Risk Indicators:
- Overall Risk Score: 80/100 (High Risk)
- Blacklist Count: 0
- Known Campaigns: None identified
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
Control Plane Observations:
- DNSBL Listings: 5 of 8 total lists
- RPKI State: Not validated in available data
- IR Consistency: Not assessed
- Route Changes (30d): 0
DNS & Email Security:
- PTR Records: None
- Forward Resolution: Not confirmed
- Hosted Domains: 0
- Email Authentication: No SPF or DMARC records detected
## Neighborhood Analysis
Subnet: 91.234.137.0/24
- Abuse Density: 12.5%
- Classification: Mostly Clean
- Total Siblings: 24
- Active Siblings: 14
- Threat Siblings: 3
High-Risk Neighbors (Risk Score β₯ 80):
- 91.234.137.40 (risk: 80)
- 91.234.137.144 (risk: 80)
Medium-Risk Neighbors (Risk Score 40-79):
- 91.234.137.34, 91.234.137.47, 91.234.137.67, 91.234.137.115, 91.234.137.152, 91.234.137.161, 91.234.137.164, 91.234.137.212, 91.234.137.230, 91.234.137.252 (all risk: 55)
- 91.234.137.54, 91.234.137.86, 91.234.137.138, 91.234.137.157 (risk: 45)
- 91.234.137.126, 91.234.137.192, 91.234.137.207, 91.234.137.240 (risk: 30)
## Observation History
The IP has generated 17 observations across multiple signal types, including:
- ASN and geolocation lookups from AlienVault OTX
- Traceroute analysis (14 hops)
- Subnet abuse density assessments
- HTTP/HTTPS connection attempts (some failed)
The IP shows no persistent malicious behavior patterns over time.
## Recommended Actions
Immediate Mitigation:
1. Block or Monitor: Given the high risk score (80) and elevated DNSBL listings (5/8), implement strict egress/ingress filtering.
2. Subnet-Wide Review: Monitor all 23 sibling IPs in the 91.234.137.0/24 subnet, particularly the two high-risk neighbors (91.234.137.40, 91.234.137.144).
3. Email Authentication: No SPF/DMARC records detected; consider blocking email traffic if this IP is used for mail relay.
4. Traffic Pattern Analysis: Investigate traffic patterns during peak hours; lighttpd server may indicate legitimate hosting or potentially compromised infrastructure.
Monitoring Recommendations:
- Enable logging for all connections to/from this IP
- Monitor for changes in BGP announcements (route stability currently false)
- Track DNSBL listing changes
- Correlate with the 3 threat siblings in the subnet for potential lateral movement indicators
## Conclusion
While 91.234.137.214 lacks direct threat indicators (no known campaigns, blacklists, or attacker signatures), its high risk score and presence within an abused subnet warrant defensive measures. The subnet's 12.5% abuse density with multiple high-risk siblings suggests potential for coordinated misuse. Recommend treating this IP as high-risk until positive reputation data emerges, and monitor the broader 91.234.137.0/24 subnet for correlated activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | PP Dmutrashko Evgeny Vitalievich |
| ASN | AS197218 |
| Network Name | LANPRO-NET |
| CIDR Block | 91.234.136.0/22 |
| RIR | RIPE |
| Country | UA |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | lighttpd/1.4.39 |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 20% | 5 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-30 23:21:07 UTC |
| Last Seen | 2026-08-01 22:42:15 UTC |
| Profile Built | 2026-07-31 05:24:26 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.