IPDebrief

91.92.242.178

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# Intelligence Briefing: 91.92.242.178/32

Classification: High Risk โ€“ Actionable Threat Intelligence

Date: 2026-07-29

Analyst: IPDebrief Intelligence Platform

---

## Executive Summary

IP address 91.92.242.178 is classified as High Risk (risk score: 80/100) and warrants defensive attention. The endpoint operates as a single-service host within the OMEGATECH (ASN 202412) network in Amsterdam, Netherlands. Despite no direct threat indicators, the combination of an open RDP port (3389/tcp), 4 DNSBL listings, and a subnet abuse density of 14.29% creates a credible attack surface.

---

## Profile Overview

AttributeValue
**IP Address**91.92.242.178/32
**Risk Score**80 (High)
**ASN**202412
**Organization**OMEGATECH
**Country**NL (Netherlands)
**City**Amsterdam
**CIDR Block**91.92.242.0/24
**Service Purpose**Single-Service Host

---

## Threat Indicators

---

## Neighborhood Analysis (91.92.242.0/24)

MetricValue
**Abuse Density**14.29%
**Total Siblings**7
**Active Siblings**6
**Threat Siblings**1
**Classification**mostly_clean

Neighbor Risk Distribution:

The subnet exhibits moderate abuse activity with one sibling (91.92.242.55) carrying elevated risk.

---

## Historical Observations (Last 16 Signals)

Recent observations indicate:

The IP has remained stable in classification despite the high risk score, suggesting a chronic rather than acute threat profile.

---

## Recommended Defensive Actions

Immediate:

1. Block inbound RDP (3389/tcp) traffic from 91.92.242.0/24 at perimeter firewall

2. Implement rate limiting on TCP port 3389 for the subnet

3. Monitor for lateral movement attempts from this subnet to internal systems

Medium-Term:

4. Add 91.92.242.0/24 to threat intelligence feed with priority flag

5. Correlate with 91.92.242.55 (highest risk sibling) for joint blocking consideration

6. Review DNSBL listings to determine specific feed origins and context

Long-Term:

7. Assess business necessity for RDP exposure in this subnet

8. Implement geo-fencing for Netherlands-originated connections requiring explicit approval

---

## Intelligence Narrative

The target IP (91.92.242.178) presents a medium-to-high risk profile characterized by operational exposure rather than active malicious activity. The open RDP port represents the primary vulnerability, enabling potential unauthorized access attempts. The subnet's 14.29% abuse density and presence of multiple medium-risk neighbors suggest this network infrastructure may be used for opportunistic abuse campaigns. While no direct attack attribution exists, the combination factors warrant defensive hardening and monitoring. The IP's lack of persistent malicious behavior and absence of known campaign correlations support a defensive posture focused on access control rather than active threat hunting.

---

Generated by IPDebrief Intelligence Platform

Tool Usage: ipdebrief_profile, ipdebrief_history, ipdebrief_relationships, ipdebrief_neighbors

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ณ๐Ÿ‡ฑ Netherlands
RegionNorth Holland
CityAmsterdam
TimezoneEurope/Amsterdam
Latitude52.13
Longitude5.29

๐Ÿข Ownership & Registration

OrganizationAbuse Contact
ASNAS202412
Network NameOMEGATECH
CIDR Block91.92.242.0/24
RIRRIPE
CountryNL
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)

๐Ÿ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeSingle-Service Host
Network TierUnknown โ€” Insufficient routing data to classify
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
3389rdptcpโ€”
Closed Ports22, 25, 80, 443, 8080, 8443 (1 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
0%
00
reputation
0%
00
geolocation
0%
00
Overall12%33
Coverage: 3/6 dimensions ยท Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-07-23 07:49:31 UTC
Last Seen2026-08-13 06:45:26 UTC
Profile Built2026-07-29 18:01:44 UTC
Data FreshnessLive
Signal Types18
Total Observations18
๐Ÿ” 18 signal types ยท 18 observations collected
This report is generated from 18+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.