IPDebrief

94.31.115.131

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING: 94.31.115.131/32

Classification: LOW RISK - Residential/Dynamic Allocation

Date of Analysis: 2026-07-29

Source: IPDebrief Intelligence Platform

---

## EXECUTIVE SUMMARY

IP 94.31.115.131 is classified as LOW RISK with a risk score of 0. The address belongs to Deutsche Glasfaser's ORTSNETZ-FTTH-DYNAMIC network (ASN 8899) and appears to be a residential fiber-to-the-home dynamic allocation. No active threat indicators, blacklist hits, or known malicious campaigns are associated with this IP.

---

## OWNERSHIP & INFRASTRUCTURE

AttributeValue
**ASN**8899
**Organization**DGNO Role account
**Netname**ORTSNETZ-FTTH-DYNAMIC
**CIDR Block**94.31.112.0/21
**RIR**RIPE
**Abuse Contact**abuse@deutsche-glasfaser.de
**Network Type**Residential FTTH (Fiber-to-the-Home)

---

## GEOLOCATION ANALYSIS

Significant geolocation inconsistencies observed:

Assessment: Geo consensus is FALSE. Multiple conflicting geolocation sources indicate this IP may have been reassigned or the data reflects routing anomalies. Deutsche Glasfaser's infrastructure primarily serves German markets, making the US signals anomalous.

---

## THREAT INDICATORS

IndicatorStatus
**Risk Score**0 (Low Risk)
**Abuse Confidence Score**Not Applicable
**Blacklist Count**0
**Known Attacker**False
**Spam Source**False
**Tor Exit Node**False
**Known Campaigns**None
**Threat Feeds**Empty

Status: No active threat indicators. IP is not flagged in any threat intelligence feeds.

---

## NETWORK SERVICES

---

## NEIGHBORHOOD ANALYSIS

Subnet: 94.31.115.0/24

Abuse Density: 0 (Low)

Total Siblings: 6

Active Siblings: 6

Neighbor Risk Distribution:

Neighbor Summary:

---

## OBSERVATION HISTORY

Total Observations: 15

Key Signals:

Temporal Analysis: No ownership changes detected. No persistent malicious activity observed.

---

## RELATIONSHIP GRAPH

Connected Entities: 2 (Both static)

No complex relationship chains detected.

---

## CONTROL PLANE

---

## RECOMMENDED ACTIONS

No immediate blocking required. This IP presents a low-risk profile consistent with residential fiber infrastructure.

Recommended Firewall Rules:

---

## ANALYST NOTES

1. Geolocation Discrepancy: The US/Boston signals appear anomalous for a German operator. Recommend verification through RDAP queries.

2. Network Classification: This is a dynamic residential allocation. Legitimate end-user traffic is expected.

3. Abuse Context: Subnet abuse density is 0, indicating this /24 is not typically used for malicious activity.

4. Risk Profile: The IP shows no evidence of malicious use. The risk score of 0 reflects its classification as a legitimate residential endpoint.

Conclusion: This IP should be treated as LOW RISK residential traffic. No immediate defensive action required unless specific threat intelligence indicates otherwise.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇩🇪 Germany
RegionBaden-Wurttemberg
CityDußlingen
TimezoneEurope/Berlin
Latitude51.17
Longitude10.45

🏢 Ownership & Registration

OrganizationDGNO Role account
ASNAS8899
Network NameORTSNETZ-FTTH-DYNAMIC
CIDR Block94.31.112.0/21
RIRRIPE
CountryDE
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)

🔐 DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown — Insufficient routing data to classify
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Server—
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS8899
Network Prefix94.31.114.0/23
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
30%
25
routing
8%
11
services
12%
22
ownership
23%
24
reputation
20%
13
geolocation
17%
23
Overall18%1018
Coverage: 1/6 dimensions · Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

📅 Observation Timeline 🔄 Live

First Seen2026-07-20 06:31:06 UTC
Last Seen2026-09-02 18:01:13 UTC
Profile Built2026-09-02 18:02:46 UTC
Data FreshnessLive
Signal Types21
Total Observations26
🔍 21 signal types · 26 observations collected
This report is generated from 21+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 94.31.115.131

Who owns the IP address 94.31.115.131?

94.31.115.131 is registered to DGNO Role account. The address falls within the 94.31.112.0/21 network block. Registration is held at RIPE.

Where is 94.31.115.131 located?

Geolocation data places 94.31.115.131 in Dußlingen, Baden-Wurttemberg, Germany. The local time zone is Europe/Berlin. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 94.31.115.131 malicious or safe?

94.31.115.131 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.

🏘️ Related IP Addresses

Nearby addresses in 94.31.112.0/21

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.