IP Intelligence Briefing: 109.243.130.95
Date: 2026-06-10
---
**Risk Assessment**
- Risk Score: 65 (Moderate Risk)
- Threat Indicators: No malicious indicators, spam, or known attacker associations detected.
- Stability: Unstable network configuration (e.g., inconsistent BGP routing, low operator score).
- Abuse Density: Subnet (109.243.128.0/18) shows no abuse activity.
---
**Ownership & Geolocation**
- Registrar: P4-MNT (ASN 39603, ARIN registry)
- Location: Mikoลów, Silesia, Poland (50.19°N, 18.88°E)
- ISP: Play Internet (play-internet.pl)
- Network Role: Firewalled host; no open ports or services detected.
---
**Network & DNS Configuration**
- DNS:
- PTR hostname: `user-109-243-130-95.play-internet.pl`
- SPF record present; no DMARC or CAA records.
- BGP:
- Origin ASN: 39603
- Route stability: Unstable (route changes detected in 30 days).
- Subnet: 109.243.128.0/18 (no neighboring IPs detected).
---
**Observation History (30 Days)**
- Signals Tracked: Geolocation (100%), network role (100%), DNS (80%).
- Key Trends:
- Stable geolocation (Poland) with inferred city coordinates.
- No persistent threat activity or malware campaigns.
- Low DNSBL listings (3/8).
---
**Relationships**
- Linked Entities:
- DNS hostname: `user-109-243-130-95.play-internet.pl`
- Same network: `PLAY_FBB` (P4-MNT).
- No Known Associations: No connections to Tor, CDN, or cloud infrastructure.
---
**Actionable Insights**
1. Monitor DNS Configuration: Ensure SPF records are properly configured and consider enabling DMARC for email security.
2. Network Stability: Investigate BGP route instability (ASN 39603) to confirm legitimate ownership.
3. Subnet Activity: Track 109.243.128.0/18 for unexpected neighbor activity, though current abuse density is low.
4. Geolocation Verification: Validate the inferred Polish location with additional probes if geolocation accuracy is critical.
---
Conclusion: 109.243.130.95 is a low-to-moderate risk IP with no direct malicious activity. Focus on ensuring DNS security and monitoring network stability. No immediate mitigation required, but ongoing observation is recommended.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | P4-MNT |
| ASN | AS39603 |
| Network Name | PLAY_FBB |
| CIDR Block | 109.243.128.0/18 |
| RIR | ARIN |
| Country | PL |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | user-109-243-130-95.play-internet.pl |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | user-109-243-130-95.play-internet.pl |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 13% | 1 | 1 |
| routing | 13% | 1 | 1 |
| services | 13% | 1 | 1 |
| ownership | 30% | 2 | 3 |
| reputation | 0% | 0 | 0 |
| geolocation | 13% | 1 | 1 |
| Overall | 14% | 6 | 7 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-25 06:40:44 UTC |
| Last Seen | 2026-06-10 20:26:53 UTC |
| Profile Built | 2026-06-10 20:59:36 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 19 |
Full dossier details are available via our API.