IPDebrief

94.181.229.245

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING: 94.181.229.245/32

## Executive Summary

IP address 94.181.229.245 is registered to JSC "ER-Telecom Holding" Kirov Branch (ASN 41727) and is classified as a Residential Endpoint with a moderate risk score of 40. The IP is located in Kirov, Russia, within the Kaluga Oblast region. While no active threat campaigns or known attacker indicators were detected, the IP maintains a moderate risk posture due to DNSBL listings and should be monitored or blocked based on organizational threat tolerance.

## Ownership and Network Attribution

AttributeValue
ASN41727
OrganizationJSC "ER-Telecom Holding" Kirov Branch
RIRRIPE
BGP Prefix94.181.228.0/22
Network ClassificationResidential Endpoint
ISP TypeTelecom Provider

## Geolocation Data

AttributeValue
CountryRussia (RU)
RegionKaluga Oblast
CityKirov
Geolocation MethodMulti-signal inference
Accuracy Radius5,000 km
Confidence0.52

## Network Behavior and Services

## Threat Indicators

IndicatorStatus
Known AttackerNo
Tor Exit NodeNo
Proxy/VPNNo
Spam SourceNo
Blacklist Count0
Campaign Matches0
DNSBL Listed2 of 8 lists
Threat PersistenceNot persistently malicious

## Risk Assessment

## Relationship Graph Analysis

The IP maintains 52 identified relationships, primarily categorized as "Same Network" connections to the ERTH-KIROV network infrastructure. No certificate-based or hostname-based relationships were identified that would indicate association with known malicious infrastructure.

## Observation History

Signal observation history indicates consistent network infrastructure attribution to ASN 41727 since at least June 2026. Geolocation data has remained stable, with multi-signal inference consistently placing the IP in Russia. No significant threat signal escalations have been observed.

## Recommended Security Actions

Based on the IP's risk profile, the following firewall rules are recommended:

iptables

```bash

iptables -A INPUT -s 94.181.229.245 -j DROP

```

nftables

```bash

nft add rule inet filter input ip saddr 94.181.229.245 drop

```

nginx

```nginx

deny 94.181.229.245;

```

pfSense

```

94.181.229.245/32

```

Cloudflare WAF

```json

{"description":"Block 94.181.229.245 โ€” IPDebrief risk score 40","action":"block","filter":{"expression":"ip.src eq 94.181.229.245"}}

```

AWS WAF

```json

{"Addresses":["94.181.229.245/32"],"Description":"IPDebrief risk 40"}

```

## Analyst Notes

The IP address 94.181.229.245 presents a moderate risk profile typical of residential endpoints associated with legitimate telecom infrastructure. The absence of open ports and known threat indicators suggests this IP may be monitoring residential traffic rather than actively hosting malicious services. However, the presence of DNSBL listings and the inherited risk score from the /24 subnet warrant defensive blocking or rate-limiting policies.

Organizations should consider:

1. Implementing the recommended firewall rules if the IP is not an expected business partner

2. Monitoring for any behavioral changes that might indicate compromise

3. Reviewing connection logs for anomalous activity patterns from this address

---

*This briefing was generated using IPDebrief intelligence platform data. All findings are based on observed network intelligence and should be correlated with additional threat indicators before operational action.*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ท๐Ÿ‡บ Russia
RegionKaluga Oblast
CityKirov
Timezoneโ€”
Latitude54.07
Longitude34.29

๐Ÿข Ownership & Registration

OrganizationJSC "ER-Telecom Holding" Kirov Branch
ASNAS41727
Network Nameโ€”
CIDR Blockโ€”
RIRRIPE
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR94x181x229x245.datakirov.com
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnames94x181x229x245.datakirov.com

๐Ÿ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureResidential
Service PurposeResidential Endpoint
Network TierEnd-User โ€” Residential ISP endpoint
Residential

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
27%
24
routing
13%
11
services
15%
22
ownership
24%
23
reputation
22%
13
geolocation
19%
22
Overall20%1015
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-11 02:52:10 UTC
Last Seen2026-06-26 07:35:58 UTC
Profile Built2026-06-26 07:42:49 UTC
Data FreshnessLive
Signal Types22
Total Observations26
๐Ÿ” 22 signal types ยท 26 observations collected
This report is generated from 22+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.