IP INTELLIGENCE BRIEFING: 94.29.38.71
Classification: High Risk Residential IP — Requires Investigation
Executive Summary
IP address 94.29.38.71 is a residential endpoint associated with MTG Mobile Network Operator (MTS PJSC) in Moscow, Russia. Despite elevated risk scoring (80/100), the IP shows no active threat indicators, is not blacklisted, and operates as a dynamic residential connection with no open services. The elevated score appears driven by DNSBL listings (5/8) and mobile carrier classification.
Technical Profile
- IP Address: 94.29.38.71
- ASN: 25513 (MGTS-USPD-MNT)
- Organization: MGTS-PPPOE (MTS PJSC)
- CIDR Block: 94.29.0.0/18
- Geolocation: Moscow, Russia (RIPE RIR)
- Network Type: Residential mobile (MTS LTE, MCC 250, MNC 01)
- DNS: Dynamic hostname (94-29-38-71.dynamic.spd-mgts.ru)
- Services: Firewalled/No services exposed
Risk Assessment
- Overall Risk Score: 80/100
- Threat Indicators: None detected
- Blacklist Count: 0
- DNSBL Listings: 5 out of 8 total lists
- Known Campaigns: None
- Tor Exit Node: No
- Spam Source: No
Observation History
19 observations recorded. Most recent activity (2026-07-27) indicates:
- Geographic consistency: Moscow coordinates (55.7487, 37.6187), 2,036.3km from probe origin
- ICMP validation: Blocked (unable to validate)
- Port scanning: No open ports detected
- TLS/HTTP services: None detected
- Ownership stability: No changes observed
Network Relationships
- Subnet Analysis: 94.29.38.0/24 — No sibling IPs with risk data
- DNS Associations: Single dynamic hostname (94-29-38-71.dynamic.spd-mgts.ru)
- Network: MGTS-PPPOE residential network
- No certificate or organizational relationships detected
Recommended Actions
Given the high risk score and DNSBL presence, the following actions are recommended:
1. Immediate: Increase logging verbosity and monitor for connection attempts
2. Network Defense:
- iptables: `iptables -A INPUT -s 94.29.38.71 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 94.29.38.71 drop`
- nginx: `deny 94.29.38.71;`
- pfSense: Add 94.29.38.71/32 to block list
- Cloudflare WAF: Block with expression `ip.src eq 94.29.38.71`
- AWS WAF: Add 94.29.38.71/32 to IP set
Operational Notes
While the risk score is elevated, this IP appears to be a residential endpoint rather than an active threat actor. The 5 DNSBL listings may be false positives or related to the dynamic nature of residential IPs. SOC teams should correlate with traffic patterns before blocking, as legitimate residential users may access this IP.
Threat Persistence: 0 days (no persistent malicious activity observed)
Campaign Correlation: None detected
Correlated IPs: 0
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | MGTS-USPD-MNT |
| ASN | AS25513 |
| Network Name | MGTS-PPPOE |
| CIDR Block | 94.29.0.0/18 |
| RIR | RIPE |
| Country | RU |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | 94-29-38-71.dynamic.spd-mgts.ru |
| Forward Confirmed | Yes — FCrDNS verified |
| Forward Hostnames | 94-29-38-71.dynamic.spd-mgts.ru |
🔐 DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 — Basic operator with some routing infrastructure |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS25513 |
| Network Prefix | 94.29.0.0/17 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 23% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 17% | 2 | 3 |
| reputation | 8% | 1 | 2 |
| geolocation | 17% | 2 | 3 |
| Overall | 14% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-15 10:09:40 UTC |
| Last Seen | 2026-08-31 11:10:27 UTC |
| Profile Built | 2026-08-31 06:53:26 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 29 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 94.29.38.71
Who owns the IP address 94.29.38.71?
94.29.38.71 is registered to MGTS-USPD-MNT. The address falls within the 94.29.0.0/18 network block. Registration is held at RIPE.
Where is 94.29.38.71 located?
Geolocation data places 94.29.38.71 in Moscow, Moscow, Russia. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 94.29.38.71 malicious or safe?
94.29.38.71 currently carries a high risk assessment, meaning indicators associated with malicious or abusive activity have been observed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 94.29.38.71?
The reverse DNS (PTR) record for 94.29.38.71 is 94-29-38-71.dynamic.spd-mgts.ru. This hostname is forward-confirmed, meaning it resolves back to the same address.
Is 94.29.38.71 a VPN, proxy, or data center address?
94.29.38.71 is classified as a mobile network based on network ownership and behavioural analysis.