# INTELLIGENCE BRIEFING: 91.92.243.236/32
Date: [Current Date]
Classification: Threat Intelligence Summary
Subject: IP Address 91.92.243.236
---
## EXECUTIVE SUMMARY
IP 91.92.243.236 is classified as Low Risk with a risk score of 0. The address currently shows no active threat indicators, no open services, and no direct evidence of malicious activity. However, contextual analysis of the /24 subnet reveals elevated abuse density that warrants monitoring.
---
## NETWORK IDENTIFICATION
- IP Address: 91.92.243.236/32
- Subnet: 91.92.243.0/24
- ASN: 202412 (OMEGATECH-AS - Omegatech LTD, SC)
- Country: TR (Turkey)
- Registration: 2006-08-15
- RIR: RIPE NCC
---
## RISK ASSESSMENT
| Metric | Value | Status |
|---|---|---|
| Risk Score | 0 | Low |
| Abuse Confidence | N/A | N/A |
| Provider Score | 0 | N/A |
| Authority Score | 0 | N/A |
Threat Indicators: None detected
- Not a known attacker
- Not a spam source
- Not a Tor exit node
- Zero blacklist listings
Network Role: Firewalled / No Services
- No open ports detected
- No active TLS certificates
- No hosted domains
- No email authentication (SPF/DMARC)
---
## BEHAVIORAL ANALYSIS
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: 0
- Active Attacker Status: False
- Auto-Banned: False
Control Plane:
- Route Stability: False
- Operator Score: 0
- DNSBL Listed Count: 0
---
## SUBNET CONTEXT (91.92.243.0/24)
Abuse Density: 6.2% (16 total IPs analyzed)
| Risk Level | Count | Representative IPs |
|---|---|---|
| High | 1 | 91.92.243.20 (Risk: 80) |
| Medium | 8 | 91.92.243.207 (Risk: 55), 91.92.243.216 (Risk: 50) |
| Low | 7 | 91.92.243.212 (Risk: 0), 91.92.243.4 (Risk: 40) |
Assessment: The /24 subnet shows moderate abuse activity with one high-risk neighbor. While 91.92.243.236 itself remains clean, the subnet context suggests this is not a benign residential block.
---
## OBSERVATION HISTORY
Total Signals Observed: 9
Recent Activity (2026-07-30):
- DNSSEC validation confirmed (dnssec_valid: true)
- ASN resolution: OMEGATECH-AS (AS202412)
- Multiple signal types captured with confidence levels ranging from 0.22 to 0.90
Temporal Indicators:
- Threat persistence: 0 days
- Ownership changes: 0
- Not persistently malicious
---
## RELATIONSHIPS
No direct relationships identified (no associated hostnames, organizations, or certificates in the relationship graph).
---
## RECOMMENDED ACTIONS
Immediate Actions: No specific firewall rules required at this time.
Monitoring Recommendations:
1. Subnet Monitoring: Monitor 91.92.243.0/24 for abuse activity, particularly 91.92.243.20 (Risk: 80)
2. Traffic Analysis: Review inbound/outbound traffic patterns for any anomalous behavior
3. Recurring Checks: Re-verify risk profile after 30 days or upon new threat indicators
Firewall Rules: None currently recommended
---
## INTELLIGENCE CONCLUSION
IP 91.92.243.236 represents a low-risk address with no current threat indicators. The IP is unpopulated (firewalled/no services) with no associated malicious activity. However, the 6.2% abuse density in the parent /24 subnet suggests this infrastructure block warrants ongoing monitoring. SOC teams should track this IP in their watchlist and prioritize subnet-level analysis should any compromise occur in related addresses.
---
*Intelligence generated by IPDebrief. Data confidence: Low. Recommend correlating with additional threat feeds before taking enforcement actions.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Abuse Contact |
| ASN | AS202412 |
| Network Name | OMEGATECH |
| CIDR Block | 91.92.243.0/24 |
| RIR | RIPE |
| Country | US |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 3389 | rdp | tcp | โ |
| Closed Ports | 22, 25, 80, 443, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 25% | 1 | 1 |
| Overall | 22% | 6 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-28 22:22:49 UTC |
| Last Seen | 2026-08-03 23:39:28 UTC |
| Profile Built | 2026-07-30 19:35:55 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 19 |
Full dossier details are available via our API.