# Intelligence Briefing: 91.92.242.178/32
Classification: High Risk โ Actionable Threat Intelligence
Date: 2026-07-29
Analyst: IPDebrief Intelligence Platform
---
## Executive Summary
IP address 91.92.242.178 is classified as High Risk (risk score: 80/100) and warrants defensive attention. The endpoint operates as a single-service host within the OMEGATECH (ASN 202412) network in Amsterdam, Netherlands. Despite no direct threat indicators, the combination of an open RDP port (3389/tcp), 4 DNSBL listings, and a subnet abuse density of 14.29% creates a credible attack surface.
---
## Profile Overview
| Attribute | Value |
|---|---|
| **IP Address** | 91.92.242.178/32 |
| **Risk Score** | 80 (High) |
| **ASN** | 202412 |
| **Organization** | OMEGATECH |
| **Country** | NL (Netherlands) |
| **City** | Amsterdam |
| **CIDR Block** | 91.92.242.0/24 |
| **Service Purpose** | Single-Service Host |
---
## Threat Indicators
- DNSBL Listings: 4 of 8 total lists (elevated presence)
- Open Ports: RDP (3389/tcp) โ potential brute force and lateral movement vector
- Operator Score: 0.1304 (Minimal) โ inconsistent with high risk classification
- Route Stability: Unstable (false) โ may indicate infrastructure volatility
- DNSSEC: Valid
---
## Neighborhood Analysis (91.92.242.0/24)
| Metric | Value |
|---|---|
| **Abuse Density** | 14.29% |
| **Total Siblings** | 7 |
| **Active Siblings** | 6 |
| **Threat Siblings** | 1 |
| **Classification** | mostly_clean |
Neighbor Risk Distribution:
- 91.92.242.55: Risk Score 70 (highest in subnet)
- 91.92.242.7: Risk Score 65
- 91.92.242.114: Risk Score 55
- 91.92.242.143: Risk Score 50
- 91.92.242.30: Risk Score 40
- 91.92.242.202: Risk Score 40
The subnet exhibits moderate abuse activity with one sibling (91.92.242.55) carrying elevated risk.
---
## Historical Observations (Last 16 Signals)
Recent observations indicate:
- Classification: mostly_clean (abuse density: 14.29%)
- No ownership changes detected
- No persistent malicious behavior observed
- No threat persistence days recorded
- No known campaigns correlated
The IP has remained stable in classification despite the high risk score, suggesting a chronic rather than acute threat profile.
---
## Recommended Defensive Actions
Immediate:
1. Block inbound RDP (3389/tcp) traffic from 91.92.242.0/24 at perimeter firewall
2. Implement rate limiting on TCP port 3389 for the subnet
3. Monitor for lateral movement attempts from this subnet to internal systems
Medium-Term:
4. Add 91.92.242.0/24 to threat intelligence feed with priority flag
5. Correlate with 91.92.242.55 (highest risk sibling) for joint blocking consideration
6. Review DNSBL listings to determine specific feed origins and context
Long-Term:
7. Assess business necessity for RDP exposure in this subnet
8. Implement geo-fencing for Netherlands-originated connections requiring explicit approval
---
## Intelligence Narrative
The target IP (91.92.242.178) presents a medium-to-high risk profile characterized by operational exposure rather than active malicious activity. The open RDP port represents the primary vulnerability, enabling potential unauthorized access attempts. The subnet's 14.29% abuse density and presence of multiple medium-risk neighbors suggest this network infrastructure may be used for opportunistic abuse campaigns. While no direct attack attribution exists, the combination factors warrant defensive hardening and monitoring. The IP's lack of persistent malicious behavior and absence of known campaign correlations support a defensive posture focused on access control rather than active threat hunting.
---
Generated by IPDebrief Intelligence Platform
Tool Usage: ipdebrief_profile, ipdebrief_history, ipdebrief_relationships, ipdebrief_neighbors
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Abuse Contact |
| ASN | AS202412 |
| Network Name | OMEGATECH |
| CIDR Block | 91.92.242.0/24 |
| RIR | RIPE |
| Country | NL |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 3389 | rdp | tcp | โ |
| Closed Ports | 22, 25, 80, 443, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-23 07:49:31 UTC |
| Last Seen | 2026-08-13 06:45:26 UTC |
| Profile Built | 2026-07-29 18:01:44 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.