# IP Intelligence Briefing: 94.183.27.167/32
Date: 2026-07-29
IP Address: 94.183.27.167
Risk Score: 15 (Low Risk)
---
## Executive Summary
The IP address 94.183.27.167 presents a low-risk threat profile with a risk score of 15. No active threat indicators detected. The IP is associated with Iranian domain infrastructure (shatel.ir) despite US geolocation reporting, warranting attention for potential spoofing or misconfiguration scenarios.
---
## Technical Profile
Geolocation:
- Country: United States (US)
- Region: New York (US-NY)
- Timezone: America/New_York
- Geolocation Consensus: Valid (1 source)
- Geolocation Plausibility: β οΈ Flagged as implausible
Network Classification:
- Origin ASN: 31549
- BGP Prefix: 94.183.16.0/20
- Route Stability: False
- DNSSEC Status: Valid
- Service Purpose: Firewalled / No Services
- Open Ports: None detected
DNS Configuration:
- PTR Hostname: 94-183-27-167.shatel.ir
- Forward Resolution: 94.183-27-167.shatel.ir
- Email Authentication: SPF and DMARC configured
- Hosted Domain Count: 0
---
## Threat Assessment
Current Threat Indicators:
- Blacklist Count: 0
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Active Threat Feeds: None
DNSBL Status:
- Listed: 1 out of 8 total DNSBL checks
- Severity: Medium (on listed sources)
Behavioral Analysis:
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: 0
- Total Incidents: 0
---
## Observation History
Total Observations: 11 signals recorded
Most Recent: 2026-07-29 17:53 UTC
Signal Timeline:
1. Operator Score: 0.1304 (Minimal risk classification)
2. Route Signals: Threat/routing/services/ownership/geolocation dimensions analyzed
3. DNSBL Listings: 1 medium-severity listing among 8 total checks
4. DNS Records: Domain shale.ir with CAA records present
5. DNSSEC: Valid signature confirmed
Temporal Indicators:
- Ownership Changes: 0
- Threat Persistence Days: 0
- Persistently Malicious: No
---
## Relationship Mapping
DNS Associations:
- Hostname: 94-183-27-167.shatel.ir
No additional relationships detected:
- No subnet associations
- No organization links
- No certificate associations
- No correlated IPs
---
## Neighborhood Analysis
Subnet: 94.183.27.167/24
Neighbor Count: 0
Abuse Density: 0%
Threat Siblings: 0
Active Siblings: 0
The /24 subnet shows no sibling activity, indicating isolated IP behavior.
---
## Recommended Actions
Current Recommendation: None
Firewall Rules: Not generated (low risk profile)
Suggested Actions:
- Monitor DNS resolution for the shale.ir domain (potential typo squatting or infrastructure indicator)
- Verify geolocation discrepancy (US location with Iranian TLD)
- Review DNSBL listing sources for context
- No immediate blocking required
---
## Intelligence Notes
Key Observations:
1. Domain mismatch: PTR hostname uses .shatel.ir domain despite US geolocation
2. Route instability detected (route changes observed)
3. DNSSEC properly validated
4. Minimal operator score (0.1304)
5. No open services or ports detected
Assessment: Low-risk infrastructure with minor anomalies. Monitor for changes in geolocation consistency or DNS configuration. No immediate threat activity observed.
---
*Report generated by IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | MNT-RASANA |
| ASN | AS31549 |
| Network Name | SHTL-NET-ARD-DSL |
| CIDR Block | 94.183.24.0/21 |
| RIR | RIPE |
| Country | IR |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 94-183-27-167.shatel.ir |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 94-183-27-167.shatel.ir |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-23 07:49:33 UTC |
| Last Seen | 2026-07-29 17:53:09 UTC |
| Profile Built | 2026-07-29 18:01:44 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 19 |
Full dossier details are available via our API.