IP Intelligence Briefing: 94.78.89.29/32
Date: 2026-06-06
---
**1. Core Profile**
- Risk Score: 80 (High Risk)
- Ownership: Registered to MNT-NETH (Turkish ISP) under ASN 44558.
- Geolocation: Mersin, Turkey (36.81°N, 34.64°E).
- Network Role: Firewalled / No Services (no open ports, no TLS/HTTP services detected).
- Threat Indicators: No direct malicious indicators (no blacklists, campaigns, or exploits).
---
**2. Network & Subnet Analysis**
- Subnet: 94.78.89.0/24
- Abuse Density: 6.67% (moderate risk).
- Neighbors:
- High-risk neighbors: 1 (94.78.89.46, 94.78.89.54, 94.78.89.56) with risk scores β₯80.
- Active siblings: 3 IPs (total 15 in subnet).
- Threat Siblings: 1 IP flagged in neighborhood.
---
**3. Threat & Behavioral Signals**
- DNS:
- PTR hostname: `94-78-89-29.netonline.net`.
- SPF/DKIM records present (email security configured).
- DNSBL Listings: 4/8 lists (moderate risk).
- BGP:
- Route stability: Unstable (recent changes).
- Operator score: 0.13 (Minimal risk).
---
**4. Historical Trends**
- Risk Stability: Fluctuating signals (last 30 days).
- Key Observations:
- Minimal operator risk (0.13 score).
- Subnet abuse density increased to 26.67% in recent scans.
---
**5. Recommendations**
- Monitor: High-risk neighbors (94.78.89.46, 94.78.89.54, 94.78.89.56) for lateral movement.
- Block: Consider blocking this IP if itβs not a trusted internal asset.
- Investigate: DNSBL listings and subnet abuse density may indicate compromised infrastructure.
Next Steps: Cross-reference with internal assets and monitor for anomalous traffic patterns.
---
*Data sourced from IPDebrief threat intelligence platform.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | MNT-NETH |
| ASN | AS44558 |
| Network Name | β |
| CIDR Block | β |
| RIR | RIPE |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 94-78-89-29.netonline.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 94-78-89-29.netonline.net |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | lighttpd/1.4.39 |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 24% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 13% | 1 | 1 |
| Overall | 18% | 9 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-11 08:59:39 UTC |
| Last Seen | 2026-06-26 09:34:56 UTC |
| Profile Built | 2026-06-26 09:43:28 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 20 |
Full dossier details are available via our API.