# IP Intelligence Briefing: 94.206.205.181/32
Classification: LOW RISK / DEFENSIVE MONITORING
Date: 2026-07-30
Analyst: Automated Intelligence System
---
## Executive Summary
IP address 94.206.205.181/32 is a mobile carrier endpoint associated with Emirates Integrated Telecom (du). The IP exhibits a low risk profile with a reputation score of 25/100. No active threat indicators, malware campaigns, or malicious behavior have been observed. The endpoint is firewalled with no open services, consistent with mobile network infrastructure. No immediate defensive action required; continue passive monitoring.
---
## Technical Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 25 (Low Risk) |
| **ASN** | 15802 (DIC-MNT) |
| **Organization** | DIC-MNT |
| **Network** | AE-DU-20080717 |
| **CIDR Block** | 94.200.0.0/13 |
| **RIR** | RIPE |
| **Geolocation** | Dubai, AE (primary); London, GB (secondary signal) |
| **Network Role** | Mobile Carrier (du) |
| **Connection Type** | LTE/5G |
| **MCC/MNC** | 424/03 |
| **Abuse Confidence** | None detected |
| **Blacklist Status** | 0/0 lists |
---
## Threat Intelligence
Current Threat Assessment
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Known Campaigns: None
- Open Ports: None
- TLS Certificate: None
- HTTP Services: None
- DNS Records: None hosted
Control Plane Data
- BGP Prefix: 94.206.192.0/19
- Route Stability: Unstable (route changes observed)
- DNSSEC Valid: Yes
- DNSBL Listings: 1 of 8 total lists
- Origin ASN: 15802
---
## Observation History (12 Signals)
Recent observations indicate consistent network infrastructure:
- Organization: DIC-MNT (consistent)
- ASN: 15802 (consistent)
- Geo Location: Dubai, AE signals dominate recent data
- Neighborhood: 94.206.205.181/24 classified as clean
- Traceroute: 14 hops to target reached
- Scans: Port scans detected but no services responding
No evidence of escalating threat behavior or persistent malicious activity over the observation window.
---
## Network Relationships
- Same Network: AE-DU-20080717 (primary relationship)
- Related Hostnames: None
- Related Certificates: None
- Associated Organizations: None beyond primary ASN
---
## Neighborhood Analysis (94.206.205.181/24)
- Abuse Density: 0.0
- Classification: Clean
- Total Siblings: 1
- Active Siblings: 0
- Threat Siblings: 0
- Risk Distribution: No high/medium risk neighbors detected
The /24 subnet shows no correlation with neighboring malicious activity.
---
## Recommended Security Actions
Risk Score: 25 (Low Risk)
- Block: No recommendation
- Monitor: Continue passive monitoring
- Firewall Rules: Not applicable (no active services)
- WAF Rules: Not required
The IP's low risk score and mobile carrier classification preclude aggressive blocking. However, network defenders should note the DNSBL listing (1 of 8 lists) and monitor for any service activation or port opening on previously firewalled endpoints.
---
## Intelligence Narrative
This IP address represents a mobile carrier endpoint (Emirates Integrated Telecom/du) operating within the 94.200.0.0/13 RIPE network block. The endpoint maintains a firewalled posture with no active services, consistent with mobile infrastructure design. Geolocation signals show the IP primarily associates with Dubai, AE, though some signals reference London, GBβthis discrepancy may reflect multi-point routing or CDN termination.
The IP has been observed 12 times with consistent organizational attribution to DIC-MNT. No threat indicators, campaign associations, or malicious behavior patterns have been identified. The neighborhood classification as "clean" with zero abuse density reinforces the benign nature of this endpoint.
Threat Level: LOW
Action: Continue passive monitoring; no immediate defensive action required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DIC-MNT |
| ASN | AS15802 |
| Network Name | AE-DU-20080717 |
| CIDR Block | 94.200.0.0/13 |
| RIR | RIPE |
| Country | AE |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-25 14:53:40 UTC |
| Last Seen | 2026-07-30 04:49:20 UTC |
| Profile Built | 2026-07-30 04:56:45 UTC |
| Data Freshness | Live |
| Signal Types | 15 |
| Total Observations | 15 |
Full dossier details are available via our API.