# IP Intelligence Briefing: 94.154.43.66/32
## Executive Summary
The target IP 94.154.43.66 presents as a low-risk infrastructure address operating within a predominantly clean subnet. The IP functions as a single-service host with SSH service exposure and maintains minimal operator-level risk characteristics. Recent observation history indicates transient DNSBL activity with high-severity listings.
## Technical Profile
Risk Assessment:
- Overall Risk Score: 25 (Low Risk)
- Reputation: Low Risk
- Provider Score: 0
- Authority Score: 0
- Stability Score: 0 (No persistent labeling)
Network Attribution:
- ASN: 219502
- Organization: ISP5HAT-MNT
- RIR Registry: RIPE
- Geolocation: Country Code UA (Ukraine), Timezone Europe/Kyiv
- Geolocation Confidence: Mixed (geoConsensus: false, geoPlausible: true)
- Network Classification: Single-Service Host
Routing & Control Plane:
- BGP Prefix: 94.154.43.0/24
- Route Stability: Unstable (isRouteStable: false)
- Route Changes (30-day): 0
- DNSSEC Validation: Valid
- Operator Score: 0.1304 (Minimal)
- DNSBL Listings: 1 of 8 total lists flagged
## Service Exposure
- Open Ports: TCP/22 (SSH)
- Service Banner: SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18
- TLS Certificate: None detected
- Hosted Domains: 0
- Email Authentication: No SPF/DMARC records configured
## Threat Intelligence
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Active Threat Indicators: None detected
- Known Campaign Correlation: None
- Blacklist Count: 0 (profile), 1 (DNSBL control plane)
## Neighborhood Analysis (94.154.43.0/24)
- Subnet Classification: Mostly Clean
- Abuse Density: 0.031 (3.1%)
- Total Siblings: 33
- Active Siblings: 7
- Threat Siblings: 5
- Risk Distribution: 1 High, 6 Medium, 24 Low
Notable High-Risk Neighbors:
- 94.154.43.230: Risk Score 80 (Critical)
- 94.154.43.50: Risk Score 65 (High)
- 94.154.43.254: Risk Score 50 (Medium)
## Historical Signal Activity
50 observations recorded. Recent activity (2026-07-27) shows:
- Multiple DNSBL listing events with high-severity classifications
- Operator score consistency at 0.1304
- Signal confidence levels: 0.30 (routing/operator), 0.85 (blacklist listings)
- No persistent malicious behavior observed
- Threat persistence days: 0
## Operational Recommendations
Traffic Handling:
- Allow standard SSH traffic to/from the IP
- Implement rate limiting on SSH connections
- Monitor for connection attempts from the target to known malicious IPs
Network Context:
- Subnet 94.154.43.0/24 contains elevated-risk neighbors requiring monitoring
- 94.154.43.230 and 94.154.43.50 should be flagged for enhanced scrutiny
- Consider correlating traffic patterns with high-risk subnet neighbors
Monitoring Priorities:
- Watch for DNSBL re-listings with high severity
- Monitor for changes in route stability
- Track SSH authentication failure rates
- Correlate with neighbor IPs showing risk score >50
## Conclusion
IP 94.154.43.66 represents low-risk infrastructure with transient DNSBL activity. The subnet context requires awareness of neighboring high-risk addresses, but the target itself shows no persistent malicious indicators. Standard defensive monitoring with attention to subnet-level activity is recommended.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | ISP5HAT-MNT |
| ASN | AS219502 |
| Network Name | — |
| CIDR Block | 94.154.43.0/24 |
| RIR | RIPE |
| Country | — |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 — Basic operator with some routing infrastructure |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS219502 |
| Network Prefix | 94.154.43.0/24 |
| Route mapping | Found |
| RPKI Status | Valid |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 5 |
| routing | 19% | 3 | 4 |
| services | 12% | 2 | 2 |
| ownership | 29% | 3 | 6 |
| reputation | 14% | 1 | 3 |
| geolocation | 17% | 2 | 3 |
| Overall | 20% | 13 | 23 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-02 04:22:25 UTC |
| Last Seen | 2026-09-10 17:30:34 UTC |
| Profile Built | 2026-09-10 17:41:18 UTC |
| Data Freshness | Live |
| Signal Types | 27 |
| Total Observations | 36 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 94.154.43.66
Who owns the IP address 94.154.43.66?
94.154.43.66 is registered to ISP5HAT-MNT. The address falls within the 94.154.43.0/24 network block. Registration is held at RIPE.
Where is 94.154.43.66 located?
Geolocation data places 94.154.43.66 in Newark, US-NJ, United States. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 94.154.43.66 malicious or safe?
94.154.43.66 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 94.154.43.66?
Responsive ports observed on 94.154.43.66 include 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.