# IP INTELLIGENCE BRIEFING: 94.31.75.189/32
## Executive Summary
IP 94.31.75.189 is a low-risk infrastructure address belonging to Deutsche Glasfaser (DGNO), a German Tier-1 fiber ISP. The address shows no active malicious indicators, no open services, and maintains a stable risk profile with a score of 25. No immediate defensive actions required based on current threat intelligence.
---
## Network Ownership & Registration
- Organization: DGNO Role account (Deutsche Glasfaser)
- Network Name: DE-DGW-20100203
- ASN: 8899 (DEUTAG)
- CIDR Block: 94.31.64.0/18
- RIR: RIPE
- Registration: Active (ownership stable, 0 changes observed)
- Abuse Contact: abuse@deutsche-glasfaser.de
---
## Geolocation
- Country: Germany (DE)
- Region: North Rhine-Westphalia
- City: Willich
- Coordinates: 51.17°N, 10.45°E
- Geo Confidence: 52% (multi-signal inference)
- Accuracy Radius: 400km
---
## Threat Assessment
- Risk Score: 25 (Low Risk)
- Abuse Confidence: Not elevated
- Blacklist Status: Listed on 1 of 8 DNSBL checks (minimal impact)
- Known Threats: None detected
- Malicious Campaigns: No associations
- Tor/Proxy/VPN: Not detected
- Tor Exit Node: No
- Known Attacker: No
---
## Network Services & Behavior
- Open Ports: None detected
- Service Status: Firewalled / No Services
- TLS Certificate: None
- HTTP Title: None
- DNS Resolution: Forward resolution not confirmed
- PTR Records: None
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: 0
---
## Control Plane Analysis
- Route Stability: False (minor route changes observed)
- Operator Score: 0.1304 (Minimal)
- BGP Prefix: 94.31.72.0/22
- RPKI State: Not reported
- DNSSEC: Valid
---
## Neighborhood Context (/24 Subnet)
- Subnet: 94.31.75.0/24
- Total Siblings: 6
- Abuse Density: 0.0 (Clean)
- Risk Distribution: 0 High, 0 Medium, 6 Low
- Correlated Risk IPs: 94.31.75.147, 94.31.75.210, 94.31.75.233 (all risk score 25)
---
## Observation History (15 Signals)
- Latest Observation: 2026-07-27T22:14:29 UTC
- Threat Persistence Days: 0
- Is Persistently Malicious: No
- Signal Types: Geographic inference, ownership resolution, port scanning
- Trend: Stable, no escalation in risk signals
---
## Recommended Actions
No immediate defensive actions recommended. The IP presents as legitimate ISP infrastructure with no active threat indicators. Standard allow policies may be applied pending additional correlation with specific security events.
---
## Analyst Notes
The address belongs to Deutsche Glasfaser's residential/business fiber network. The low risk score, absence of open services, and clean neighborhood profile indicate this is normal ISP traffic. Monitor for any correlation with specific security incidents, but no proactive blocking is warranted at this time.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | DGNO Role account |
| ASN | AS8899 |
| Network Name | DE-DGW-20100203 |
| CIDR Block | 94.31.64.0/18 |
| RIR | RIPE |
| Country | DE |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS8899 |
| Network Prefix | 94.31.72.0/22 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-15 10:09:41 UTC |
| Last Seen | 2026-09-01 00:27:23 UTC |
| Profile Built | 2026-08-30 20:40:54 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 21 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 94.31.75.189
Who owns the IP address 94.31.75.189?
94.31.75.189 is registered to DGNO Role account. The address falls within the 94.31.64.0/18 network block. Registration is held at RIPE.
Where is 94.31.75.189 located?
Geolocation data places 94.31.75.189 in Willich, North Rhine-Westphalia, Germany. The local time zone is Europe/Berlin. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 94.31.75.189 malicious or safe?
94.31.75.189 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.