# IP INTELLIGENCE BRIEFING: 91.92.243.49
## Executive Summary
Target IP 91.92.243.49 presents a moderate risk profile (risk score 65/100) with evidence of blacklist inclusion and association with the OMEGATECH infrastructure (ASN 202412). The IP is geolocated to New York, US, but exhibits inconsistent routing stability. While no active services are currently detected, historical data indicates elevated threat activity within its /24 subnet.
## Risk Assessment
- Overall Risk Score: 65 (Moderate Risk)
- Reputation Label: Moderate Risk
- Provider/Authority Scores: 0 (neutral)
- Stability: Route instability detected; origin ASN 202412 shows route changes
## Threat Indicators
- DNSBL Listings: Listed on 3 of 8 threat feeds with high-severity classification
- Tor/Proxy/VPN: No indicators
- Known Campaigns: None identified
- Service Exposure: Firewalled/no services detected (no open ports)
- Email Reputation: No email authentication records (SPF, DMARC)
## Neighborhood Analysis
Subnet 91.92.243.0/24 demonstrates mixed-use characteristics:
- Abuse Density: 0.231
- Total Siblings: 13
- High-Risk Neighbors: 3 IPs (91.92.243.4, 91.92.243.15, 91.92.243.20) with risk scores of 80
- Threat Correlation: 3 threat siblings identified in the same /24
## Temporal Observations
- Observation Count: 17 historical signals
- Recent Activity: Last observed June 25, 2026
- Historical Blacklists: Multiple high-severity listings recorded on June 12 and June 25, 2026
- Threat Persistence: Not persistently malicious
## Infrastructure Classification
- Network: OMEGATECH (ASN 202412)
- Geolocation: New York, US (2,500 km accuracy radius)
- RIR: RIPE
- Control Plane: Route not stable; operator score 0.1304 (Minimal)
## Recommended Actions
- Monitoring: Add to watchlist for continued DNSBL listing verification
- Network Filtering: Consider blocking at perimeter if internal policy prohibits OMEGATECH traffic
- Neighbor Investigation: Investigate the three high-risk sibling IPs (91.92.243.4, 91.92.243.15, 91.92.243.20)
- Inbound Traffic: Monitor for connection attempts from this subnet
## Conclusion
This IP represents a moderate-risk threat with documented blacklist history and association with a network exhibiting elevated abuse density. While currently inactive (firewalled), the neighborhood context warrants continued monitoring and consideration of blocking policies.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Abuse Contact |
| ASN | AS202412 |
| Network Name | β |
| CIDR Block | β |
| RIR | RIPE |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 24% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 20% | 9 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-09 11:34:25 UTC |
| Last Seen | 2026-06-25 17:25:11 UTC |
| Profile Built | 2026-06-25 17:31:01 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 16 |
Full dossier details are available via our API.