# IP Intelligence Briefing: 94.154.43.183/32
Classification: Low Risk | Risk Score: 25 | Date: 2026-07-24
## Executive Summary
IP address 94.154.43.183 presents a low-risk profile with no active threat indicators. The IP is firewalled with no open services detected and resides in a subnet characterized as "mostly_clean." No recommended blocking actions are generated based on current risk assessment.
## Ownership & Infrastructure
- ASN: 219502 (ISP5HAT-MNT)
- Network: NET-94-15-40 /94.154.40.0/22
- RIR: RIPE
- Geolocation: US (Newark, NJ)
- BGP Origin: 94.154.43.0/24
- Route Stability: Unstable (isRouteStable: false)
- Operator Score: 0.1304 (Minimal)
## Threat Assessment
- Risk Score: 25/100
- Reputation: Low Risk
- Abuse Confidence Score: Not applicable
- Blacklist Count: 0
- DNSBL Listed: 1 of 8 lists
- Known Campaigns: None detected
- Tor Exit/Proxy: Negative
- Known Attacker: Negative
- Spam Source: Negative
## Network Services & Behavior
- Open Ports: None detected
- Service Purpose: Firewalled / No Services
- TLS Certificate: None
- HTTP Title: None
- Honeypot Hits: 0
- WAF Violations: 0
- Enumeration Strikes: 0
## Neighborhood Analysis (94.154.43.0/24)
- Total Siblings: 31
- Active Siblings: 4
- Threat Siblings: 5
- Abuse Density: 0.1613
- Classification: Mostly Clean
- Inherited Risk: 6
Risk distribution across subnet:
- High Risk: 0
- Medium Risk: 3
- Low Risk: 27
Notable higher-risk neighbors:
- 94.154.43.50 (Risk: 65)
- 94.154.43.181 (Risk: 50)
- 94.154.43.254 (Risk: 50)
## Historical Observations (16 Signals)
Recent observations show:
- 2026-07-24 13:07:09: Neighborhood classification "mostly_clean" with abuse density 0.1613
- 2026-07-24 13:05:03: No persistent malicious activity detected
- 2026-07-24 13:05:10: Geolocation signal from MaxMind indicating Ukraine (50.4522, 30.5287)
- 2026-07-24 13:08:52: Multi-signal inference placing IP in US
Geographic signals show inconsistency between US (Newark, NJ) and Ukraine coordinates, indicating potential geolocation spoofing or routing anomalies.
## Control Plane Data
- RPKI State: Not available
- IRR Consistency: Not available
- Route Changes (30d): 0
- DNSSEC Valid: Yes
- DNSBL Lists: 1 (of 8 total)
## Recommended Security Actions
No specific firewall rules or blocking recommendations generated. The IP's low-risk profile and lack of active threat indicators suggest continued monitoring is appropriate without immediate mitigation measures.
## Intelligence Conclusions
The IP 94.154.43.183 demonstrates characteristics consistent with passive infrastructure. Key findings:
1. No active threat indicators or malicious behavior observed
2. Firewalled status prevents direct service enumeration
3. Subnet shows low abuse density with minimal risk inheritance
4. Geographic signal inconsistencies warrant monitoring but do not indicate active threat
5. No persistent malicious activity in historical records
Recommendation: Maintain standard monitoring protocols. No immediate action required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | ISP5HAT-MNT |
| ASN | AS219502 |
| Network Name | NET-94-15-40 |
| CIDR Block | 94.154.40.0/22 |
| RIR | RIPE |
| Country | US |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS219502 |
| Network Prefix | 94.154.43.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 16% | 4 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-07 12:36:08 UTC |
| Last Seen | 2026-08-26 23:08:29 UTC |
| Profile Built | 2026-08-29 07:08:07 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 19 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 94.154.43.183
Who owns the IP address 94.154.43.183?
94.154.43.183 is registered to ISP5HAT-MNT. The address falls within the 94.154.40.0/22 network block. Registration is held at RIPE.
Where is 94.154.43.183 located?
Geolocation data places 94.154.43.183 in Newark, US-NJ, United States. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 94.154.43.183 malicious or safe?
94.154.43.183 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 94.154.43.183?
Responsive ports observed on 94.154.43.183 include 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.