# IP Intelligence Briefing: 94.156.152.190/32
Classification: Low Risk | Report Date: 2026-07-26
## Executive Summary
Target IP 94.156.152.190 exhibits low-risk characteristics with a reputation score of 0. The address is associated with RIPE registration block 94.156.152.0/24 under organization "INTERNET-MAGNATE." Current assessment indicates no active threat indicators, with the IP classified as "Firewalled / No Services."
## Technical Profile
| Attribute | Value |
|---|---|
| **IP Address** | 94.156.152.190/32 |
| **Risk Score** | 0 |
| **Provider Score** | 0 |
| **Authority Score** | 0 |
| **Organization** | INTERNET-MAGNATE-MNT |
| **Registration** | RIPE |
| **CIDR Block** | 94.156.152.0/24 |
| **Geolocation** | US, Newark, NJ (America/New_York) |
| **Network Role** | Firewalled / No Services |
## Threat Indicators
- Blacklist Count: 0
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Threat Feeds: Empty
- Open Ports: None
- TLS Certificate: None
- Active Services: None
## Observation History Analysis
Thirteen historical observations recorded. Key findings:
- Geographic Variance: Recent geolocation signals show conflicting data between US (Newark, NJ) and Bulgaria (BG, coordinates 42.696, 23.332). This inconsistency warrants monitoring but does not indicate malicious activity.
- Subnet Classification: Classified as "clean" with abuse density of 0.
- DNSSEC: Validated on reverse zone 190.152.156.94.in-addr.arpa.
- Blacklist Exposure: Some historical observations indicate blacklist listings with "high" severity (8 total lists, 3 listed).
## Neighborhood Assessment
Subnet 94.156.152.0/24 analysis:
- Abuse Density: 0%
- Total Siblings: 5
- Active Siblings: 3
- Threat Siblings: 0
Neighbor Risk Distribution:
- 94.156.152.8: Risk 49/50 (Medium-High)
- 94.156.152.18: Risk 15/50 (Low-Medium)
- 94.156.152.48: Risk 40/50 (Medium)
- 94.156.152.70: Risk 0/50 (Clean)
## Network Relationships
- Same Network: INTERNET-MAGNATE (94.156.152.0/24)
- No additional related entities detected in relationship graph.
## Recommended Actions
| Action Type | Priority | Rationale |
|---|---|---|
| **Monitor Geographic Inconsistencies** | Medium | Conflicting US/BG geolocation signals may indicate misconfiguration or spoofing attempts |
| **Watch Neighbor 94.156.152.8** | Low | Higher risk score (49) may warrant periodic review |
| **Standard Traffic Logging** | Low | No immediate threat indicators; maintain baseline logging |
| **No Blocking Required** | N/A | IP not identified as malicious source |
## Intelligence Assessment
The target IP maintains a clean threat profile with no evidence of malicious activity. The subnet demonstrates low abuse density, though one neighbor IP (94.156.152.8) shows elevated risk metrics. The geolocation inconsistency between US registration data and Bulgaria-based geolocation signals should be tracked but does not currently indicate compromise.
Disposition: Accept with monitoring. No immediate mitigation required.
---
*Report generated from IPDebrief intelligence platform data. All metrics derived from automated analysis of network signals and threat feeds.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | INTERNET-MAGNATE-MNT |
| ASN | AS214209 |
| Network Name | INTERNET-MAGNATE |
| CIDR Block | 94.156.152.0/24 |
| RIR | RIPE |
| Country | ZA |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | mail.vintagecanvas.net |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | mail.vintagecanvas.net |
🔐 DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 6 days |
🛡️ Public Network Snapshot
| Origin ASN | AS214209 |
| Network Prefix | 94.156.152.0/24 |
| Route mapping | Found |
| HSTS | Not detected |
| CSP | Not detected |
| HTTP/2 | Enabled |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 37% | 2 | 5 |
| ownership | 17% | 2 | 3 |
| reputation | 8% | 1 | 2 |
| geolocation | 23% | 2 | 4 |
| Overall | 20% | 10 | 19 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-11 08:23:29 UTC |
| Last Seen | 2026-09-02 16:10:24 UTC |
| Profile Built | 2026-09-02 16:16:56 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 33 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 94.156.152.190
Who owns the IP address 94.156.152.190?
94.156.152.190 is registered to INTERNET-MAGNATE-MNT. The address falls within the 94.156.152.0/24 network block. Registration is held at RIPE.
Where is 94.156.152.190 located?
Geolocation data places 94.156.152.190 in Sofia, 22, South Africa. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 94.156.152.190 malicious or safe?
94.156.152.190 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 94.156.152.190?
The reverse DNS (PTR) record for 94.156.152.190 is mail.vintagecanvas.net. This hostname is not forward-confirmed, so it should be treated as a weak signal.