# INTELLIGENCE BRIEFING: 95.140.40.84/32
## Executive Summary
Target IP 95.140.40.84 presents a MODERATE RISK profile (Risk Score: 40) associated with Hungarian infrastructure provider SZNET. No active threat indicators detected; IP is not classified as known attacker, spam source, or Tor exit node. Neighborhood classification indicates mostly_clean subnet with low abuse density.
## Ownership and Infrastructure
- ASN: 41075 (ATW NOC)
- Organization: SZNET (Hungarian network provider)
- CIDR Block: 95.140.40.0/24
- Geolocation: Hungary (Budapest area, 47.16°N, 19.5°E)
- Registration: Ripe registry
- PTR Hostname: 95-140-40-84.szervernet.hu
## Network Classification
- Infrastructure Type: No services detected (Firewalled / No Services)
- Connection Type: Not cloud, CDN, VPN, proxy, or hosting
- Mobile Carrier: None
- BGP Prefix: 95.140.40.0/21
- Route Stability: Not stable (0 route changes in 30 days)
- DNSSEC: Valid
## Threat Indicators
- Threat Indicators: None detected
- Blacklist Status: Listed on 2 of 8 DNSBLs
- Known Campaigns: None
- Abuse Confidence: Not scored
- Threat Feeds: Empty
- Honeypot Hits: 0
- Enumeration Strikes: 0
## DNS Analysis
- Forward Resolution: 1 hostname (95-140-40-84.szervernet.hu)
- Reverse Resolution: 1 hostname (95-140-40-84.szervernet.hu)
- Forward Confirmed: No
- Email Auth: SPF record present; DMARC status unknown
- Hosted Domains: 0
## Observations and History
- Total Observations: 19
- Observation Period: Recent activity recorded (July 2026 timeframe)
- Threat Observation Count: 1
- Is Persistently Malicious: No
- Ownership Changes: 0
- Threat Persistence Days: 0
Recent Activity:
- Geo-location validation: Plausible (1043.9km distance from probe; 113.6ms average RTT)
- Traceroute: 18 hops, target reached successfully
- DNSBL Listings: 2 lists flagged with high severity
## Neighborhood Analysis
- Subnet: 95.140.40.84/24
- Abuse Density: 1 (Low)
- Classification: Mostly Clean
- Inherited Risk: 2
- Total Siblings: 1
- Threat Siblings: 1
## Network Relationships
- Network Associations: SZNET (multiple instances)
- DNS Associations: 95-140-40-84.szervernet.hu (3 instances)
## Recommended Actions
1. Monitoring: Monitor for service activation; currently no open ports detected
2. Blocking: DNSBL listings indicate potential reputation concerns; evaluate blocking based on organizational policy
3. Threat Intel: No immediate blocking required; maintain baseline monitoring
4. Correlation: Investigate the 1 threat sibling within the subnet if additional context suggests related activity
## Risk Assessment
The IP addresses a legitimate Hungarian network infrastructure with no evidence of active malicious activity. The moderate risk score (40) appears driven by DNSBL listings rather than direct threat indicators. Recommended to treat as LOW-PRIORITY monitoring target unless additional contextual intelligence suggests otherwise.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | ATW NOC |
| ASN | AS41075 |
| Network Name | SZNET |
| CIDR Block | 95.140.40.0/24 |
| RIR | RIPE |
| Country | HU |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | 95-140-40-84.szervernet.hu |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 95-140-40-84.szervernet.hu |
🔐 DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS41075 |
| Network Prefix | 95.140.40.0/21 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 0% | 0 | 0 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 25% | 1 | 1 |
| geolocation | 25% | 1 | 1 |
| Overall | 20% | 5 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-16 16:44:44 UTC |
| Last Seen | 2026-08-31 20:44:35 UTC |
| Profile Built | 2026-08-31 20:45:58 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 24 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 95.140.40.84
Who owns the IP address 95.140.40.84?
95.140.40.84 is registered to ATW NOC. The address falls within the 95.140.40.0/24 network block. Registration is held at RIPE.
Where is 95.140.40.84 located?
Geolocation data places 95.140.40.84 in Hungary. The local time zone is Europe/Budapest. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 95.140.40.84 malicious or safe?
95.140.40.84 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 95.140.40.84?
The reverse DNS (PTR) record for 95.140.40.84 is 95-140-40-84.szervernet.hu. This hostname is not forward-confirmed, so it should be treated as a weak signal.
What ports are open on 95.140.40.84?
Responsive ports observed on 95.140.40.84 include 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.