IPDebrief

92.118.39.29

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 92.118.39.29/32

## Executive Summary

The target IP address 92.118.39.29 was classified as a moderate risk multi-service host with an overall risk score of 40. The address operates within a /24 subnet exhibiting elevated abuse density, with 23 of 40 sibling IPs flagged as threats. Historical observation data indicates consistent moderate-risk classification over the monitoring period with no evidence of persistent malicious activity.

## Network Classification and Ownership

The IP address was identified as belonging to ASN 47890 under RIPE NCC registration. The profile indicated an abuse contact role object with geolocation data pointing to the Netherlands (NL) with regional assignment to Texas, Dallas. The address operated as a multi-service host rather than a cloud, CDN, VPN, or proxy service.

## Service Fingerprint and Port Exposure

Network scans revealed the target host running:

The HTTP fingerprint showed standard Apache headers with HTTP/1.1 protocol support, 200 OK response status, and a time-to-first-byte (TTFB) of 265ms. The server lacked HSTS, Content Security Policy, or HTTP/2 configuration.

## Threat Indicators and Reputation

Threat indicators analysis returned no known malicious activity. The IP was not identified as:

Blacklist analysis showed zero blacklist entries despite one DNSBL listing across eight monitored lists. Campaign correlation returned no matches, with zero correlated IPs and zero certificate subject matches.

## Neighborhood Analysis

The target IP resides within the 92.118.39.0/24 subnet, which demonstrated high abuse classification. The neighborhood analysis revealed:

Risk distribution within the subnet showed 12 high-risk IPs, 26 medium-risk IPs, and 2 low-risk IPs. Notable high-risk neighbors included:

## Control Plane and Routing

BGP routing data showed the origin ASN as 47890 with BGP prefix 92.118.39.0/24. The route exhibited instability, with isRouteStable flagged as false. RPKI state and IRR consistency data returned null values. DNSSEC validation was confirmed as valid.

## Historical Observation Trends

The monitoring system recorded 19 observations over the observation period. Signal types included network classification, ownership, geolocation, reputation, and routing data. Confidence levels ranged from 0.21 to 0.30 across observations. The timeline showed:

## Relationship Graph

The IP relationship graph returned 15 relationships, all classified as "Same Network" type with target values of "DMZHOST." No external relationships to hostnames, organizations, or certificates were identified.

## Recommendations

Based on the moderate risk classification and subnet-level abuse density, the following defensive measures are recommended:

1. Monitor closely: The subnet's high abuse classification (0.575 density) warrants enhanced monitoring of this IP and its neighbors

2. Block SSH port 22: Standard hardening measure for exposed SSH services

3. Monitor HTTP activity: Port 80 traffic should be logged and analyzed for anomalies

4. Watch neighborhood: The 23 threat siblings within the /24 subnet suggest coordinated abuse activity may exist

5. No immediate block: The moderate risk score (40) and lack of direct threat indicators suggest continued monitoring rather than immediate blocking

## Conclusion

IP 92.118.39.29 presents as a moderately risky multi-service host within a high-abuse subnet. While the IP itself showed no direct threat indicators, the neighborhood context and elevated abuse density suggest maintaining elevated vigilance. The address operated consistently throughout the observation period with no evidence of escalation or persistent malicious behavior.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ณ๐Ÿ‡ฑ Netherlands
RegionTexas
CityDallas
TimezoneEurope/Amsterdam
Latitude52.13
Longitude5.29

๐Ÿข Ownership & Registration

OrganizationAbuse contact role object
ASNAS47890
Network Nameโ€”
CIDR Blockโ€”
RIRRIPE
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)

๐Ÿ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeMulti-Service Host
Network TierUnknown โ€” Insufficient routing data to classify
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
22sshtcp
Closed Ports25, 443, 3389, 8080, 8443 (2 open / 7 scanned)
ServerApache/2.4.58 (Ubuntu)
HTTP Titleโ€”
SSH VersionSSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
27%
23
routing
13%
11
services
24%
23
ownership
27%
23
reputation
13%
12
geolocation
19%
22
Overall20%1014
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-07 23:04:42 UTC
Last Seen2026-06-24 01:12:56 UTC
Profile Built2026-06-24 01:21:13 UTC
Data FreshnessLive
Signal Types18
Total Observations18
๐Ÿ” 18 signal types ยท 18 observations collected
This report is generated from 18+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.