# IP Intelligence Briefing: 94.26.3.162/32
Date: July 31, 2026
Classification: Low Risk
Risk Score: 25/100
## Executive Summary
IP address 94.26.3.162 presents a low-risk profile (score: 25) with minimal threat indicators. The address is associated with ASN 135392 under the organization "Abuse mailbox" within the 94.26.3.0/24 CIDR block. Geolocation data indicates placement in Edison, New Jersey, United States. No persistent malicious activity or campaign associations have been identified.
## Technical Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 25 (Low Risk) |
| **ASN** | 135392 |
| **Organization** | Abuse mailbox |
| **Country** | United States (US) |
| **Region/City** | NJ, Edison |
| **DNS Classification** | Single-Service Host |
| **Blacklist Count** | 0 |
| **Known Attacker** | No |
| **Spam Source** | No |
| **Tor Exit** | No |
## Network Services & Ports
- Open Ports: TCP/3389 (RDP)
- TLS Certificate: None
- HTTP Title: None
- Forward Resolution: Incomplete (0 confirmed)
- PTR Records: None
## Threat Indicators
No active threat indicators detected:
- No known attack campaigns
- No blacklist listings
- No threat feed associations
- Zero abuse confidence score
- No honeypot hits recorded
## Historical Observations
The IP has generated 15 signal observations, with the most recent activity recorded on July 31, 2026. Historical signals indicate:
- Operator Score: 0.1304 (Minimal)
- Threat Persistence: 0 days
- Ownership Stability: No changes observed
- Subnet Abuse Density: 1 (classified as "mostly_clean")
- Threat Observation Count: 1 (isolated incident)
- Persistently Malicious: No
The history shows intermittent network scanning activity and geographic inference variations across observation windows.
## Neighborhood Analysis
Subnet: 94.26.3.0/24
- Abuse Density: 0-1 (minimal)
- Classification: Mostly clean
- Total Siblings: 1 active
- Threat Siblings: 1
- High/Medium Risk Neighbors: 0
No significant neighboring threat actors identified in the /24 subnet.
## Related Entities
Relationship graph contains 3 network-level associations, all classified as "Same Network" (ipv4). No organizational, hostname, or certificate relationships were resolved.
## Recommended Actions
Based on the low-risk profile (score: 25), no immediate blocking or firewall restrictions are recommended. The IP does not meet threshold criteria for:
- Explicit blocking rules
- WAF challenges
- Rate limiting beyond standard thresholds
Suggested Monitoring: Continue standard traffic monitoring. The presence of open RDP (3389) warrants awareness but does not constitute an immediate threat indicator without corroborating attack activity.
## Intelligence Conclusion
IP 94.26.3.162 demonstrates a benign operational profile with low-risk characteristics. The single open RDP port and minimal historical activity suggest a standard host rather than a compromised or malicious endpoint. SOC teams may treat this IP as low-priority for threat intelligence correlation while maintaining standard logging practices.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Abuse mailbox |
| ASN | AS135392 |
| Network Name | ipv4 |
| CIDR Block | 94.26.3.0/24 |
| RIR | RIPE |
| Country | US |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 3389 | rdp | tcp | β |
| Closed Ports | 22, 25, 80, 443, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 25% | 1 | 1 |
| geolocation | 25% | 1 | 1 |
| Overall | 26% | 7 | 8 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-30 04:59:45 UTC |
| Last Seen | 2026-07-31 19:33:31 UTC |
| Profile Built | 2026-07-31 01:31:06 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 19 |
Full dossier details are available via our API.