# IP Intelligence Briefing: 91.92.215.12/32
Classification: Moderate Risk
Date of Analysis: 2026-07-22
Analyst: IPDebrief Intelligence Team
---
## Executive Summary
Target IP 91.92.215.12 presents a moderate risk profile (score: 50) with inconsistent geolocation data. The IP is associated with RIPE RIR infrastructure, potentially linked to Data Planner (Tehran) based on ownership signals. Two DNSBL listings detected across 8 total threat intelligence feeds. No active services or campaigns observed. Route stability flags indicate potential infrastructure changes.
---
## Ownership and Geolocation
ASN/Infrastructure:
- Origin ASN: 58224
- BGP Prefix: 91.92.208.0/21
- RIR Registry: RIPE
- Route Status: Unstable (isRouteStable: false)
- RPKI State: Not verified
Geolocation Discrepancy:
- Profile Location: US (Boston, MA)
- Historical Signals: IR (Tehran, Iran)
- Multiple sources report conflicting origin data
- Geo validation shows inconsistent plausibility scores
Contact Information:
- Abuse Email: abuse-tehran@tci.ir
---
## Threat Indicators
DNSBL Status:
- Total Lists: 8
- Listed Count: 2
- Max Severity: High
- Status: Active listings require monitoring
Campaign Indicators:
- Known Campaigns: None identified
- Threat Feeds: No active matches
- Pulsedive Risk: Not assessed
Behavioral Analysis:
- Is Tor Exit: No
- Is Known Attacker: No
- Is Spam Source: No
- Active Attacker Status: No
- Honeypot Hits: 0
- WAF Violations: 0
---
## Network Services
Open Ports: None detected
TLS Certificate: Not present
HTTP Services: Not detected
DNS Records:
- PTR Hostnames: None
- Forward Resolution: Not confirmed
- Hosted Domains: 0
Control Plane:
- Origin ASN: 58224
- Route Changes (30d): 0
- DNSSEC Valid: Yes
- DNSBL Listed: 2 of 8 lists
---
## Neighborhood Analysis
Subnet: 91.92.215.12/24
- Total Siblings: 0
- Active Siblings: 0
- Threat Siblings: 0
- Abuse Density: 0
- Inherited Risk: 0
- Classification: Clean
No neighboring IPs identified within the /24 subnet.
---
## Relationship Graph
Related Entities: None identified
- Associated Subnets: None
- Hostnames: None
- Organizations: None
- Certificates: None
---
## Observation History
Total Observations: 13
Recent Signals (2026-07-22):
- RIR: RIPE
- Organization: Data Planner (Tehran)
- Country: IR
- CIDR: 91.92.212.0/22
- Abuse Contact: abuse-tehran@tci.ir
- Geo Validation: Tehran coordinates (35.698N, 51.4115E)
- ICMP Validation: Blocked (unable to validate)
- Blacklist Status: 2 of 8 lists with high severity
---
## Recommended Actions
Firewall/Network Rules:
- Monitor for DNSBL listing changes
- Flag route stability anomalies
- Investigate geolocation discrepancies
- Apply moderate-risk filtering policies
Monitoring Priorities:
- Track DNSBL listing updates
- Monitor for service discovery
- Watch for relationship emergence
- Alert on route prefix changes
Severity Rating: Moderate
Action Required: Monitor and track
---
*Report generated from IPDebrief intelligence platform. Data sourced from multiple threat intelligence feeds and historical observations.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Data Planner (Tehran) |
| ASN | AS58224 |
| Network Name | TCITHR |
| CIDR Block | 91.92.212.0/22 |
| RIR | RIPE |
| Country | IR |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS58224 |
| Network Prefix | 91.92.208.0/21 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 20% | 2 | 2 |
| routing | 8% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 17% | 2 | 3 |
| reputation | 14% | 1 | 2 |
| geolocation | 12% | 2 | 2 |
| Overall | 13% | 9 | 11 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-02 04:22:23 UTC |
| Last Seen | 2026-09-29 03:09:19 UTC |
| Profile Built | 2026-09-04 19:53:41 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 43 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 91.92.215.12
Who owns the IP address 91.92.215.12?
91.92.215.12 is registered to Data Planner (Tehran). The address falls within the 91.92.212.0/22 network block. Registration is held at RIPE.
Where is 91.92.215.12 located?
Geolocation data places 91.92.215.12 in Boston, US-MA, United States. The local time zone is America/New_York. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 91.92.215.12 malicious or safe?
91.92.215.12 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.