# IP INTELLIGENCE BRIEFING
Target IP: 94.250.23.44/32
Classification: Web Server / Hosting Infrastructure
Risk Score: 40/100 (Moderate Risk)
Report Date: Current Cycle
Analyst: IPDebrief Intelligence Unit
---
## EXECUTIVE SUMMARY
Target IP 94.250.23.44 is a web server hosting infrastructure owned by TELEKOM-SRPSKE-MNT (AS59847, WIRAC-NET) with registration in the Federation of Bosnia and Herzegovina. The IP presents moderate risk (40/100) with no active threat indicators, but exhibits geolocation inconsistencies and is listed on 2 of 8 DNS blacklists. No malicious activity observed in signal history.
---
## OWNERSHIP & NETWORK CONTEXT
| Attribute | Value |
|---|---|
| **Organization** | TELEKOM-SRPSKE-MNT, d.o.o. |
| **Netname** | WIRAC-NET |
| **ASN** | AS59847 |
| **CIDR Block** | 94.250.20.0/22 |
| **RIR** | RIPE |
| **Abuse Contact** | Available via RDAP |
Neighborhood Analysis: Subnet 94.250.23.0/24 classified as clean with 0% abuse density. No threat siblings detected among peers.
---
## GEOLOCATION DATA
| Field | Value |
|---|---|
| **Country** | Bosnia and Herzegovina (BA) |
| **City** | GraΔanica |
| **Coordinates** | 44.7°N, 18.3°E |
| **RTT** | 131ms (minimum) / 134.2ms (average) |
| **Geo Consensus** | False (3 sources, inconsistent) |
| **Geo Plausible** | True |
Note: Historical signal shows geolocation inconsistencyβone probe returned China (CN) with 2,500km accuracy radius, suggesting possible routing anomalies or certificate-based spoofing.
---
## THREAT INTELLIGENCE
Current Indicators:
- Threat Score: 0
- Known Campaigns: None
- Blacklist Count: 0 (malware/threat feeds)
- DNSBL Listed: 2/8 total lists
- Tor Exit: No
- Known Attacker: No
- Spam Source: No
Network Role: Web Server (HTTP/HTTPS)
Control Plane:
- Route stability: False
- RPKI State: Not verified
- DNSSEC: Valid
- Operator Score: 0.1304 (Minimal)
---
## TECHNICAL SERVICES
| Port | Protocol | Service |
|---|---|---|
| 80 | TCP | HTTP |
| 443 | TCP | HTTPS |
TLS Certificate:
- Issuer: CN=Huawei Fixed Network Product CA, O=Huawei, C=CN
- Subject: CN=ont.huawei.com, O=Huawei, C=CN
- Self-signed: No
DNS Status:
- PTR Hostnames: None
- Forward Resolution: Failed
- Hosted Domains: 0
- Email Auth (SPF/DMARC): Not configured
---
## OBSERVATION HISTORY
Total Signals: 18 observations
Recent Activity:
- 2026-07-31: Multiple probes completed
- Geolocation signals show inconsistent country attribution (BA vs CN)
- HTTP/HTTPS responses normal (200 OK)
- No threat persistence detected
Temporal Analysis:
- Ownership Changes: 0
- Threat Observation Count: 0
- Is Persistently Malicious: No
---
## SOC ACTIONS & RECOMMENDATIONS
Risk Assessment: Moderate (40/100) β Requires monitoring but does not warrant immediate block.
Recommended Actions:
- Firewall: Review existing rules for this IP
- WAF: Apply allow/block rules based on organizational policy
- Monitoring: Continue observing for threat indicator emergence
- DNSBL: Investigate 2 DNS blacklist entries for context
Platform-Specific Rules:
```bash
# iptables
iptables -A INPUT -s 94.250.23.44 -j DROP
# nftables
nft add rule inet filter input ip saddr 94.250.23.44 drop
# Cloudflare WAF
{"description": "Block 94.250.23.44 β IPDebrief risk score 40", "action": "block", "filter": {"expression": "ip.src eq 94.250.23.44"}}
```
---
## CONCLUSION
IP 94.250.23.44 is infrastructure associated with a legitimate telecom provider (Huawei) operating from Bosnia and Herzegovina. No active malicious activity detected. The moderate risk score reflects geolocation inconsistencies and DNSBL presence rather than confirmed threats. Recommend monitoring rather than immediate blocking.
Status: Clear for operation with monitoring
Next Review: 30 days or upon threat indicator emergence
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | TELEKOM-SRPSKE-MNT |
| ASN | AS59847 |
| Network Name | WIRAC-NET |
| CIDR Block | 94.250.20.0/22 |
| RIR | RIPE |
| Country | BA |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | 2020-08-25T06:59:49+00:00 |
| Valid Until | 2030-08-23T06:59:49+00:00 |
| TLS Protocol | Tls12 |
| Cipher Suite | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256RSA |
| Validity Period | 3650 days |
| Serial Number | 70C23220C046B365 |
| Thumbprint | 228081E0B7EB3A5507BBD820C56F3683EF573084 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 16% | 4 | 5 |
| Data Coherence | Mixed Signals (68%) β 2 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
β TLS certificate claims CN but primary geo says BA
π Observation Timeline π Live
| First Seen | 2026-07-30 23:21:09 UTC |
| Last Seen | 2026-08-01 16:34:00 UTC |
| Profile Built | 2026-07-31 05:11:55 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 22 |
Full dossier details are available via our API.