IP INTELLIGENCE BRIEFING: 94.154.43.56/32
Generated: 2026-07-27 | Classification: Network Defense
---
**EXECUTIVE SUMMARY**
IP 94.154.43.56 is currently classified as low risk with no active threat indicators. The address belongs to subnet 94.154.43.0/24, which exhibits moderate abuse density (0.031). No services are currently accessible on this host.
---
**CURRENT RISK PROFILE**
- Risk Score: 0 (Low Risk)
- Reputation: Low Risk
- Abuse Confidence Score: None
- Blacklist Status: Not listed (0 listings)
- Network Role: Firewalled / No Services Detected
- Open Ports: None
- Known Campaigns: None
**OWNERSHIP & GEOLOCATION**
- ASN: 219502 (STORMCLOUD-AS - Storm Industries LLC, US)
- Registration: 2011-05-20
- RIR: RIPE NCC
- Primary Geolocation: US, New Jersey (US-NJ)
- Secondary Geolocation: Ukraine (UA) - Historical observation
- Timezone: America/New_York
**NETWORK INFRASTRUCTURE**
- DNSSEC: Valid
- Reverse DNS PTR: 56.43.154.94.in-addr.arpa
- Forward Resolution: Confirmed (0 hostnames)
- Email Authentication: No SPF or DMARC records
- HTTP Services: None detected
**SUBNET ANALYSIS (94.154.43.0/24)**
- Total Siblings: 32
- Abuse Density: 0.031
- Risk Distribution:
- High Risk: 1 IP
- Medium Risk: 6 IPs
- Low Risk: 24 IPs
- Threat Siblings: 6 identified
**NOTABLE HIGH-RISK NEIGHBORS**
| IP Address | Risk Score | Authority Score |
|---|---|---|
| 94.154.43.230 | 80 | 50 |
| 94.154.43.50 | 65 | 50 |
| 94.154.43.64 | 55 | 50 |
**OBSERVATION HISTORY**
- Total Observations: 12
- Recent Geo Changes: Ukraine geolocation observed (2026-07-27)
- DNSSEC Status: Valid
- Threat Persistence: None detected
- Auto-Banned: No
---
**THREAT INTELLIGENCE ASSESSMENT**
Current Threat Level: LOW
This IP address shows no active malicious indicators. The IP is firewalled with no services running, reducing its utility as an attack vector. However, the subnet demonstrates moderate abuse density, indicating potential for nearby malicious activity.
Key Concerns:
1. Geographic data inconsistency (US vs. Ukraine) warrants monitoring
2. One high-risk neighbor (94.154.43.230) at risk score 80 may indicate coordinated abuse
3. Subnet abuse density of 0.031 suggests non-negligible threat presence in /24
No Direct Threat Indicators:
- No blacklist listings
- No known attacker patterns
- No spam or tor exit node activity
- No scanning or honeypot hits
---
**RECOMMENDED ACTIONS**
Firewall Rules:
No immediate blocking required. Standard monitoring applies.
Monitoring Priorities:
1. Track 94.154.43.230 (risk score 80) for continued threat activity
2. Monitor subnet 94.154.43.0/24 for emerging threats
3. Watch for geolocation changes indicating infrastructure relocation
IOC Generation:
- No IOCs generated for this IP
- Consider monitoring subnet range 94.154.43.0/24
- Flag 94.154.43.230, 94.154.43.50, 94.154.43.64 for correlation analysis
---
Analyst Notes: This IP requires routine monitoring due to subnet context, though the specific address shows benign characteristics. The geographic inconsistency between primary (US) and historical (Ukraine) data suggests possible infrastructure changes or data source discrepancies that warrant continued observation.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | ISP5HAT-MNT |
| ASN | AS219502 |
| Network Name | NET-94-15-40 |
| CIDR Block | 94.154.40.0/22 |
| RIR | RIPE |
| Country | US |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 0% (None) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS219502 |
| Network Prefix | 94.154.43.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 0% | 0 | 0 |
| Overall | 8% | 2 | 2 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-13 15:25:29 UTC |
| Last Seen | 2026-09-29 20:38:07 UTC |
| Profile Built | 2026-09-25 14:23:57 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 24 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 94.154.43.56
Who owns the IP address 94.154.43.56?
94.154.43.56 is registered to ISP5HAT-MNT. The address falls within the 94.154.40.0/22 network block. Registration is held at RIPE.
Where is 94.154.43.56 located?
Geolocation data places 94.154.43.56 in Newark, US-NJ, United States. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 94.154.43.56 malicious or safe?
94.154.43.56 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 94.154.43.56?
Responsive ports observed on 94.154.43.56 include 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.