IPDebrief

94.219.98.239

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 94.219.98.239/32

Classification: Moderate Risk

Date: July 30, 2026

Analyst: IPDebrief Intelligence

---

## Executive Summary

IP 94.219.98.239 presents a moderate risk profile (Score: 40) with no active threat indicators currently observed. The IP resolves to a Vodafone IP residential pool and is associated with 2 DNSBL listings. No open services or active campaigns detected. Recommend monitoring with blocking rules for inbound traffic.

---

## Network Profile

AttributeValue
**IP Address**94.219.98.239/32
**Risk Score**40/100 (Moderate)
**Geolocation**United States, New York (US-NY)
**ASN**3209
**BGP Prefix**94.216.0.0/13
**Provider**Vodafone IP
**Reverse DNS**dslb-094-219-098-239.094.219.pools.vodafone-ip.de
**Forward DNS**Confirmed

---

## Threat Indicators

Note: While DNSBL listings indicate some reputation issues, no active exploit attempts or campaign signatures were observed during the analysis period.

---

## Network Behavior

The IP appears to be part of a residential broadband pool rather than a dedicated hosting infrastructure.

---

## Observation History

12 total signals observed. Recent activity includes:

No persistent malicious activity pattern detected. Threat persistence days: 0.

---

## Relationship Analysis

Direct Associations:

No organizational, subnet, or certificate relationships beyond the DNS association.

---

## Neighborhood Assessment

The IP exists in isolation within its /24 subnet with no adjacent high-risk addresses.

---

## Recommended Actions

Firewall Rules:

```bash

# iptables

iptables -A INPUT -s 94.219.98.239 -j DROP

# nftables

nft add rule inet filter input ip saddr 94.219.98.239 drop

```

WAF Integration:

Rationale: The moderate risk score combined with DNSBL listings warrants defensive blocking, particularly for inbound traffic. The IP's residential nature suggests it could be a compromised end-user device or misconfigured system.

---

## Conclusion

IP 94.219.98.239 represents a moderate risk residential address with historical DNSBL associations. Current threat indicators are minimal, but the IP should be blocked or rate-limited per organizational policy. Monitor for any changes in reputation or behavior.

---

*Intelligence generated by IPDebrief. Recommended to validate with internal logs and threat feeds before implementing blocking rules.*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฉ๐Ÿ‡ช Germany
RegionRheinland-Pfalz
CityWehr
TimezoneEurope/Berlin
Latitude51.17
Longitude10.45

๐Ÿข Ownership & Registration

OrganizationVodafone Germany IP Core Backbone
ASNAS3209
Network NameARCOR-DSL-NET18
CIDR Block94.219.0.0/16
RIRRIPE
CountryDE
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRdslb-094-219-098-239.094.219.pools.vodafone-ip.de
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnamesdslb-094-219-098-239.094.219.pools.vodafone-ip.de

๐Ÿ” DNS Hygiene

Hygiene Score60% (Good)
SPFPresent
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureMobile
Service PurposeFirewalled / No Services
Network TierTier 3 โ€” Basic operator with some routing infrastructure
Mobile

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
0%
00
reputation
0%
00
geolocation
0%
00
Overall12%33
Coverage: 3/6 dimensions ยท Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-07-25 14:53:40 UTC
Last Seen2026-07-30 04:49:30 UTC
Profile Built2026-07-30 04:56:45 UTC
Data FreshnessLive
Signal Types19
Total Observations19
๐Ÿ” 19 signal types ยท 19 observations collected
This report is generated from 19+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.