# IP Intelligence Briefing: 92.38.9.114/32
Classification: Low Risk / Minimal Activity
Date: 2026-07-24
Analyst: SOC Intelligence
## Executive Summary
IP address 92.38.9.114 presents a low-risk profile with no active services or known threat indicators. The IP operates within a stable network environment with no observable malicious behavior in recent observation windows.
## Network Profile
- IP Address: 92.38.9.114/32
- Geolocation: Stockholm, Sweden (SE)
- Timezone: Europe/Stockholm
- Network Role: Firewalled / No Services
- Risk Score: 0 (Low Risk)
## Threat Indicators
- Abuse Confidence Score: Not applicable
- Blacklist Status: No active listings
- Known Campaigns: None detected
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
## Ownership & Infrastructure
- ASN: Not resolved in profile
- Organization: Not resolved
- Infrastructure Type: Not classified
- Service Purpose: Firewalled / No Services
## Observation History (9 Observations)
Recent signal activity from 2026-07-24 indicates:
- DNSSEC Status: Valid
- PTR Records: None present
- ASN Detection: INFOBOX-AS (47726), prefix 92.38.8.0/21
- Listings: One recent signal detected with 8 total blacklist listings (1 active), maximum severity "high"
- Geolocation Consensus: Mixed signals (SE/CZ discrepancy noted in historical data)
## Network Neighborhood Analysis
- Subnet: 92.38.9.114/24
- Abuse Density: 0
- Threat Siblings: 0
- Neighbor Count: 0
- Classification: No inherited risk
## Relationship Graph
- Related Entities: None detected
- Subnet Links: None
- Hostname Links: None
- Organization Links: None
- Certificate Links: None
## Behavioral Analysis
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: 0
- Total Incidents: 0
- Active Attacker Status: False
- Auto-Banned: False
## Recommended Actions
No immediate security actions recommended. The IP presents minimal threat characteristics with no open services, no threat indicators, and no active malicious behavior patterns.
## Intelligence Assessment
This IP address demonstrates minimal network activity with no evidence of malicious usage. The single recent blacklist listing signal requires contextual review but does not indicate persistent threat behavior. The lack of DNS resolution, absence of open ports, and zero relationship links suggest this is either a dormant IP or part of a firewalled infrastructure segment. SOC teams may monitor for changes in service status or emergence of threat indicators in future observation windows.
Confidence Level: Medium (limited historical data)
Threat Severity: Low
Recommended Priority: Monitor
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Infobox MChJ NOC |
| ASN | AS47726 |
| Network Name | INFOBOX-NET |
| CIDR Block | 92.38.8.0/21 |
| RIR | RIPE |
| Country | UZ |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS47726 |
| Network Prefix | 92.38.8.0/21 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 4% | 1 | 1 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-06 12:09:39 UTC |
| Last Seen | 2026-08-27 02:47:51 UTC |
| Profile Built | 2026-08-29 04:42:10 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 19 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 92.38.9.114
Who owns the IP address 92.38.9.114?
92.38.9.114 is registered to Infobox MChJ NOC. The address falls within the 92.38.8.0/21 network block. Registration is held at RIPE.
Where is 92.38.9.114 located?
Geolocation data places 92.38.9.114 in Qibray, Tashkent Region, Czechia. The local time zone is Europe/Prague. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 92.38.9.114 malicious or safe?
92.38.9.114 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.