## IP Intelligence Briefing: 91.234.139.33/32
Date: 2026-07-29
Analyst: IPDebrief Intelligence Team
Classification: Threat Intelligence Summary
---
EXECUTIVE SUMMARY
IP address 91.234.139.33 is classified as HIGH RISK with an overall risk score of 70/100. The IP is registered to Ukrainian entity PP Dmutrashko Evgeny Vitalievich under the LANPRO-NET network block (91.234.136.0/22). No active malicious services or open ports detected, though the IP maintains a persistent high-risk classification across observation cycles.
---
IP BASIC IDENTIFICATION
| Attribute | Value |
|---|---|
| IP Address | 91.234.139.33/32 |
| Risk Score | 70 (High Risk) |
| ASN | 197218 |
| Organization | PP Dmutrashko Evgeny Vitalievich |
| Netname | LANPRO-NET |
| Country | Ukraine (UA) |
| City | Chernivtsi |
| RIR | RIPE |
| CIDR Block | 91.234.136.0/22 |
| Abuse Contact | fastvd@gmail.com |
---
NETWORK ROLE & SERVICE PROFILE
Classification: Firewall / No Services Detected
- Open Ports: None detected
- TLS Certificate: Not present
- HTTP Title: Not available
- DNS Records: No forward resolution, no PTR hostnames
- Email Authentication: No SPF/DMARC records
- Network Type: Not CDN, VPN, Proxy, Tor, or Cloud infrastructure
---
THREAT INDICATORS & REPUTATION
| Indicator | Status |
|---|---|
| Is Tor Exit Node | No |
| Is Known Attacker | No |
| Is Spam Source | No |
| Blacklist Count | 0 |
| DNSBL Listed | 4 of 8 total lists |
| Pulsedive Risk | Not available |
| Known Campaigns | None identified |
Threat Assessment: While the IP carries a high risk classification (70/100), no active threat indicators were detected. The IP is not identified as a Tor exit node, known attacker, or spam source. However, DNSBL listing on 4 of 8 threat feeds suggests historical or passive reputation issues.
---
GEOLOCATION VALIDATION
- Primary Location: Chernivtsi, Ukraine (Region 77)
- Geo Sources: 2 sources (consensus: true)
- Accuracy Radius: 500km
- Geo Plausible: False (some geographic discrepancy noted)
- Timezone: Europe/Kyiv
---
OBSERVATION HISTORY (14 Observations)
Recent Activity (2026-07-29):
- Ownership signals consistently show no changes
- ASN 197218 registered to PP Dmutrashko Evgeny Vitalievich
- Multiple geolocation sources confirm Ukraine/Chernivtsi
- Threat observation count: 1
- Is Persistently Malicious: False
- Threat Persistence Days: 0
Temporal Stability:
- Ownership changes: 0
- Route changes (30-day): 0
- Route stable: False
- Threat persistence: None observed
---
NEIGHBORHOOD ANALYSIS (91.234.139.0/24)
Subnet Profile:
- Total Siblings: 18 IPs
- Abuse Density: 0.056 (Moderate)
- Risk Distribution: 1 High, 11 Medium, 4 Low
High-Risk Neighbors:
| IP Address | Risk Score | Authority Score |
|---|---|---|
| 91.234.139.87 | 80 | 50 |
| 91.234.139.33 | 70 | 50 |
| 91.234.139.220 | 70 | 50 |
Notable Pattern: The /24 subnet shows elevated risk concentration with 3 IPs scoring 70-80, suggesting potential coordinated activity or shared infrastructure abuse.
---
RELATIONSHIP GRAPH
- Same Network: LANPRO-NET (2 relationships identified)
- Related Entities: No additional relationships beyond network affiliation
---
CONTROL PLANE DATA
| Metric | Value |
|---|---|
| Origin ASN | 197218 |
| BGP Prefix | 91.234.136.0/22 |
| RPKI State | Not available |
| IRR Consistency | Not available |
| Route Changes (30d) | 0 |
| DNSSEC Valid | Yes |
| Operator Score | 0.1304 (Minimal) |
---
RECOMMENDED ACTIONS
For SOC/Security Teams:
1. Monitor Closely: Given the 70-risk score and neighborhood concentration of high-risk IPs (91.234.139.87, 91.234.139.220), implement enhanced logging and monitoring for traffic from this /24 block.
2. DNSBL Review: Investigate the 4 DNSBL listings to determine if this indicates historical abuse or false positives.
3. Network Context: The subnet shows elevated abuse density (0.056) with 11 medium-risk neighbors. Consider implementing egress filtering or rate limiting for the 91.234.136.0/22 block.
4. Geographic Considerations: Ukraine-based IPs may be subject to geopolitical intelligence monitoring. Validate traffic legitimacy based on business requirements.
5. Contact for Abuse: Abuse contact available via RDAP; email fastvd@gmail.com for abuse reporting if malicious activity is confirmed.
---
END OF BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | PP Dmutrashko Evgeny Vitalievich |
| ASN | AS197218 |
| Network Name | LANPRO-NET |
| CIDR Block | 91.234.136.0/22 |
| RIR | RIPE |
| Country | UA |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 0% | 0 | 0 |
| Overall | 18% | 5 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-24 08:19:14 UTC |
| Last Seen | 2026-07-29 23:01:21 UTC |
| Profile Built | 2026-07-29 23:11:13 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.