# IP Intelligence Briefing: 93.152.221.138/32
Date: Current
Classification: Moderate Risk
Risk Score: 50/100
---
## Executive Summary
Target IP 93.152.221.138 presents a moderate risk profile (score: 50) with an open RDP port and multiple DNSBL listings. While the subnet 93.152.221.0/24 is classified as "clean" with zero abuse density, the target IP warrants monitoring due to its individual threat indicators.
---
## Network Attribution
| Attribute | Value |
|---|---|
| **IP Address** | 93.152.221.138/32 |
| **ASN** | 197170 |
| **Organization** | mnt-bg-eurocrypt-1 |
| **RIR** | RIPE |
| **Country** | BG (Bulgaria) |
| **CIDR Block** | 93.152.221.0/24 |
| **Service Type** | Single-Service Host |
---
## Threat Indicators
- Risk Score: 50/100 (Moderate)
- DNSBL Listings: 2 of 8 total lists
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Blacklist Count: 0
- Campaign Correlation: None detected
---
## Service Exposure
- Port 3389/TCP: Open (RDP)
- PTR Records: None
- Forward DNS Resolution: Not confirmed
- HTTP/HTTPS Services: None detected
---
## Subnet Analysis
Subnet: 93.152.221.0/24
- Classification: Clean
- Abuse Density: 0
- Total Siblings: 15
- Active Siblings: 9
- Threat Siblings: 0
- Risk Distribution: 6 medium-risk, 8 low-risk neighbors
Notable Neighbors:
- 93.152.221.91 (Risk: 50)
- 93.152.221.118 (Risk: 50)
- 93.152.221.206 (Risk: 50)
---
## Historical Observations
Total observations: 17
Recent Activity (2026-07-31):
- Geolocation signals indicating Boston, US-MA (confidence: 0.85)
- Traceroute analysis: 30 hops, target not reached
- ASN signals: AS3320 (Deutsche Telekom AG) referenced
- Subnet classification remained consistent: "clean"
Temporal Stability:
- Ownership changes: 0
- Threat persistence days: 0
- Not persistently malicious
---
## Network Relationships
Four relationship entities identified, all categorized as "Same Network" (IPv4). No certificate, hostname, or organization relationships detected.
---
## Recommended Actions
Immediate Mitigation:
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 93.152.221.138 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 93.152.221.138 drop` |
| pfSense | `93.152.221.138/32` |
| Cloudflare WAF | Block with description: "IPDebrief risk score 50" |
| AWS WAF | Add to blocklist: 93.152.221.138/32 |
| nginx | `deny 93.152.221.138;` |
Operational Notes:
- Block recommendation based on risk score 50 and open RDP port
- Monitor subnet 93.152.221.0/24 for correlation of activity from medium-risk neighbors
- Verify geolocation discrepancy (BG country vs US-MA region data)
---
## Assessment
The target IP exhibits moderate risk characteristics primarily driven by open RDP access and DNSBL presence. The subnet-level cleanliness suggests isolated risk rather than coordinated abuse. Recommended approach: block at perimeter, maintain monitoring, and investigate any connection attempts for potential credential-based attacks.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | mnt-bg-eurocrypt-1 |
| ASN | AS197170 |
| Network Name | IPv4 |
| CIDR Block | 93.152.221.0/24 |
| RIR | RIPE |
| Country | DE |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 3389 | rdp | tcp | โ |
| Closed Ports | 22, 25, 80, 443, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 20% | 5 | 6 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-30 23:21:08 UTC |
| Last Seen | 2026-08-08 04:22:42 UTC |
| Profile Built | 2026-07-31 05:12:57 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.