# INTELLIGENCE BRIEFING: 93.177.102.89
## EXECUTIVE SUMMARY
IP 93.177.102.89 presents a Low Risk profile with a risk score of 25. The IP is associated with legitimate infrastructure in Istanbul, Turkey, operating as a single-service host with minimal threat indicators. No active malicious campaigns or persistent threat activity detected.
## OWNERSHIP & INFRASTRUCTURE
- ASN: 210538 (LIR-TR-2E-TELEKOMUNIKASYON-1-MNT)
- Organization: lir-tr-2e-telekomunikasyon-1-MNT
- Network: TR-2E-TELEKOMUNIKASYON-20181122 (93.177.100.0/22)
- RIR: RIPE
- Geolocation: Istanbul, Turkey (TR)
- Timezone: Europe/Istanbul
## NETWORK CLASSIFICATION
- Role: Single-Service Host
- Cloud/CDN/Proxy: No
- Hosting Infrastructure: No
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Route Stability: Stable (isRouteStable: true)
- RPKI State: Null
- DNSSEC: Valid
- DNSBL Listed: 1 of 8 total lists
## THREAT INDICATORS
- Abuse Confidence Score: Not available
- Blacklist Count: 0
- Pulsedive Risk: Not available
- Known Campaigns: None
- Threat Feeds: Empty
- Is Persistently Malicious: False
- Threat Observation Count: 1
## SERVICE EXPOSURE
- Open Ports: 3389/TCP (RDP)
- DNS PTR: server.keyubu.com
- Forward Resolution: server.keyubu.com
- TLS Certificate: None detected
- HTTP Banner: None
## OBSERVATION HISTORY (30 Observations)
- Most Recent Signal: 2026-06-26T17:37:20 UTC
- Domain Association: keyubu.com
- CAA Records: Present (5 issuers)
- Ownership Changes: 0
- Threat Persistence: 0 days
- Signal Confidence Range: 0.20-0.85
## NETWORK NEIGHBORHOOD (93.177.102.0/24)
- Abuse Density: 0 (Clean)
- Classification: Clean
- Threat Siblings: 0
- Total Siblings: 1
- Active Siblings: 1
## RELATED ENTITIES
- DNS Hostname: server.keyubu.com (14 DNS associations)
- Network: TR-2E-TELEKOMUNIKASYON-20181122 (11 network associations)
## ASSESSMENT & RECOMMENDATIONS
Threat Level: LOW
The IP address demonstrates stable network behavior with no evidence of malicious activity. The RDP service exposure (port 3389) represents a potential attack vector but does not indicate current compromise. The single DNSBL listing suggests minor reputation concerns requiring monitoring.
Recommended Actions:
1. Monitor RDP service exposure for unauthorized access attempts
2. Review DNSBL listing context and determine if delisting is warranted
3. Continue standard threat intelligence monitoring
4. No immediate blocking recommended based on current risk profile
Risk Delta: N/A (single IP analysis)
Campaign Likelihood: None
Correlated IPs: 0
---
*Report generated based on IPDebrief intelligence platform data.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | lir-tr-2e-telekomunikasyon-1-MNT |
| ASN | AS210538 |
| Network Name | TR-KEYUBU |
| CIDR Block | 93.177.102.0/24 |
| RIR | RIPE |
| Country | TR |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | server.keyubu.com |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | server.keyubu.com |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 3389 | rdp | tcp | โ |
| Closed Ports | 22, 25, 80, 443, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 4 |
| routing | 30% | 3 | 4 |
| services | 15% | 2 | 2 |
| ownership | 41% | 3 | 5 |
| reputation | 28% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 27% | 13 | 20 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (65%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-12 09:42:00 UTC |
| Last Seen | 2026-06-26 17:36:24 UTC |
| Profile Built | 2026-06-26 17:44:54 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 27 |
Full dossier details are available via our API.