IP INTELLIGENCE BRIEFING: 93.86.237.132
Classification: Moderate Risk | Date: 2026-07-29
---
**EXECUTIVE SUMMARY**
IP 93.86.237.132 is a low-activity ISP address with a moderate risk score (40/100). The address belongs to AS8400 (TELEKOM-BB-NET) with geolocation data indicating Vienna, Austria, though ASN records show TELEKOM SRBIJA a.d., RS. No active services are detected on the address. The /24 subnet demonstrates clean classification with zero threat siblings.
---
**OWNERSHIP & INFRASTRUCTURE**
- ASN: 8400 (TELEKOM-BB-NET)
- Organization: TELEKOM SRBIJA a.d., RS
- CIDR Block: 93.86.233.0/24
- RIR: RIPE
- Registration Date: 2008-03-12
- Geolocation: Austria (AT), Vienna
- Service Status: Firewalled / No Services
---
**THREAT INDICATORS**
- Risk Score: 40 (Moderate Risk)
- Blacklist Count: 0
- DNSBL Listings: 2 of 8 total lists (high severity categories observed)
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Threat Feeds: None detected
---
**NETWORK BEHAVIOR**
- Open Ports: None detected
- DNS Resolution: 93-86-237-132.dynamic.isp.telekom.rs
- Reverse DNS: Confirmed (forward resolution count: 1)
- DNSSEC: Valid (confirmed in observations)
- Route Stability: Unstable (isRouteStable: false)
- BGP Prefix: 93.86.0.0/16
- Route Changes (30d): 0
---
**NEIGHBORHOOD ANALYSIS**
- Subnet: 93.86.237.132/24
- Abuse Density: 0
- Classification: Clean
- Total Siblings: 3
- Active Siblings: 2
- Threat Siblings: 0
- Nearby IPs: 93.86.237.164 (risk: 40), 93.86.237.199 (risk: 40)
---
**OBSERVATION HISTORY**
- Total Observations: 14
- Recent Trends: Subnet consistently classified as "clean" with zero threat siblings
- Key Signals: DNSSEC validation confirmed, ASN resolution consistent, DNSBL listings with high severity categories
- Threat Persistence: 0 days
---
**RELATED ENTITIES**
- Same Network: TELEKOM-BB-NET (appears in two relationship entries)
- DNS Association: 93-86-237-132.dynamic.isp.telekom.rs
- Email Auth: SPF and DMARC records present
---
**RECOMMENDED ACTIONS**
Based on risk profile and DNSBL listings, consider the following firewall rules:
```bash
# iptables
iptables -A INPUT -s 93.86.237.132 -j DROP
# nftables
nft add rule inet filter input ip saddr 93.86.237.132 drop
# nginx
deny 93.86.237.132;
# Cloudflare WAF
Expression: ip.src eq 93.86.237.132
Action: block
# AWS WAF
Addresses: 93.86.237.132/32
Description: IPDebrief risk 40
```
---
**ANALYST NOTES**
The moderate risk score stems primarily from DNSBL listings rather than active threat indicators. The IP shows no evidence of malicious activity but is flagged by multiple blacklist sources. The subnet environment is clean with no correlated threat activity. Monitor for changes in DNSBL listing status or emergence of open services. The geolocation discrepancy (Austria vs. Serbia registration) warrants periodic revalidation but does not indicate malicious intent.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | AS8400-MNT |
| ASN | AS8400 |
| Network Name | TELEKOM-BB-NET |
| CIDR Block | 93.86.233.0/24 |
| RIR | RIPE |
| Country | RS |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 93-86-237-132.dynamic.isp.telekom.rs |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | 93-86-237-132.dynamic.isp.telekom.rs |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 4% | 1 | 2 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-22 19:33:36 UTC |
| Last Seen | 2026-07-29 15:46:14 UTC |
| Profile Built | 2026-07-29 15:58:11 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 19 |
Full dossier details are available via our API.