# IP INTELLIGENCE BRIEFING: 134.249.13.141/32
## Executive Summary
Target IP 134.249.13.141 is a low-risk residential broadband connection assigned to Kyivstar network infrastructure in Kyiv, Ukraine. Risk score of 25/100 with no active malicious indicators. Requires standard monitoring without immediate blocking action.
---
## Infrastructure Profile
Network Classification: Residential Broadband
ISP Organization: Kyivstar (broadband.kyivstar.net)
ASN: 15895 | BGP Prefix: 134.249.0.0/16
Geolocation: Kyiv, Ukraine (UA) | Coordinates: 49.69°N, 30.76°E
Timezone: Europe/Kyiv
Service Status: Firewalled/No Services Detected
- No open ports identified
- No TLS certificates present
- No HTTP services running
- Forward DNS resolution failed
---
## Threat Indicators
Risk Score: 25 (Low Risk)
Threat Classification: Clean with minor concerns
| Indicator | Status |
|---|---|
| Known Attacker | No |
| Tor Exit Node | No |
| Spam Source | No |
| Blacklist Count | 1 of 8 lists |
| Honeypot Hits | 0 |
| Enumeration Strikes | 0 |
| WAF Violations | 0 |
DNSBL Status: Single listing detected across 8 total DNSBL feeds. Maximum severity: high.
Control Plane: Route changes: 0 (30d) | RPKI State: Unknown | IRR Consistency: Unknown
---
## Observation History
Total Observations: 14 signals recorded
Most Recent Activity: 2026-07-28
Key Historical Signals:
- Subnet classification: Clean, abuse density 0
- Geolocation inference: Kyiv, UA (confidence: 60%)
- DNSSEC validation: Valid (true)
- DNS records: PTR to 134-249-13-141.broadband.kyivstar.net
- One blacklist listing signal with high severity rating
Temporal Analysis: No persistent malicious behavior. Zero threat persistence days.
---
## Relationship Mapping
Direct Associations: 2 relationships identified
- DNS Association: 134-249-13-141.broadband.kyivstar.net (x2)
No associations detected with:
- Other organizations
- Related subnets
- Malicious certificates
- Known campaigns
---
## Neighborhood Analysis
Subnet: 134.249.13.141/24
Neighbor Count: 0 siblings detected
Abuse Density: 0%
Risk Distribution: High: 0 | Medium: 0 | Low: 0
No neighboring IPs show elevated risk profiles.
---
## Recommended Actions
Current Risk Posture: Monitor but do not block
Firewall Rules: None required at this time
WAF Configuration: Standard rules applicable
Threat Intelligence: Add to watchlist for continued monitoring
Justification: Low risk score (25) with no active malicious behavior. Single DNSBL listing does not justify blocking for legitimate residential traffic. Geo validation failure and forward DNS resolution issues are consistent with residential broadband characteristics.
---
## Intelligence Assessment
This IP represents legitimate residential broadband infrastructure with minimal threat indicators. The combination of zero open services, no attack signatures, and residential classification supports classification as low-risk. The single DNSBL listing warrants awareness but does not elevate threat posture. Standard SOC monitoring procedures apply.
Classification: LOW RISK
Action Required: Continue monitoring
Priority: Standard
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Kyivstar PJSC |
| ASN | AS15895 |
| Network Name | KYIVSTAR-NET-5 |
| CIDR Block | 134.249.0.0/18 |
| RIR | ARIN |
| Country | UA |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | 134-249-13-141.broadband.kyivstar.net |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 134-249-13-141.broadband.kyivstar.net |
🔐 DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS15895 |
| Network Prefix | 134.249.0.0/16 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 17% | 2 | 3 |
| reputation | 20% | 1 | 3 |
| geolocation | 12% | 2 | 2 |
| Overall | 15% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-16 04:31:04 UTC |
| Last Seen | 2026-09-03 02:55:03 UTC |
| Profile Built | 2026-09-03 03:02:18 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 26 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 134.249.13.141
Who owns the IP address 134.249.13.141?
134.249.13.141 is registered to Kyivstar PJSC. The address falls within the 134.249.0.0/18 network block. Registration is held at ARIN.
Where is 134.249.13.141 located?
Geolocation data places 134.249.13.141 in Kyiv, 30, Ukraine. The local time zone is Europe/Kyiv. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 134.249.13.141 malicious or safe?
134.249.13.141 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 134.249.13.141?
The reverse DNS (PTR) record for 134.249.13.141 is 134-249-13-141.broadband.kyivstar.net. This hostname is not forward-confirmed, so it should be treated as a weak signal.