# IP Intelligence Briefing: 143.92.158.116/32
Classification: Moderate Risk | Risk Score: 50 | Status: Active
## Executive Summary
IP 143.92.158.116 is a residential broadband endpoint in Dammam, Saudi Arabia, operated by SAUDINET-STC (Saudi Telecom Company). The IP operates on mobile infrastructure (LTE/5G) with no open services detected. While the IP carries a moderate risk score of 50, current threat indicators are absent, and no persistent malicious activity has been observed.
## Ownership and Geolocation
- ASN: 25019 (SAUDINET-STC)
- Organization: SAUDINET-STC
- Network: Dammam-Residential-Fixed-Broadband (143.92.144.0/20)
- Country: Saudi Arabia (SA)
- Region: Eastern Province
- City: Dammam
- Provider: STC (Saudi Telecom Company)
- Connection Type: Mobile (LTE/5G technology)
- Mobile Carrier: MCC 420, MNC 01
## Network Services
- Open Ports: None detected
- Service Status: Firewalled / No Services
- TLS/HTTP: No active services, no certificates, no HTTP titles
- DNS Resolution: No PTR records, no forward resolution, no hosted domains
## Threat Indicators
- Blacklist Count: 0
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Abuse Confidence Score: Not available
Control Plane Analysis:
- Operator Score: 0.1304 (Minimal)
- DNSBL Listed: 2 of 8 lists
- Route Stability: False
- DNSSEC: Valid
- IRR Consistency: Not available
## Neighborhood Assessment (143.92.158.0/24)
- Abuse Density: 1
- Classification: mostly_clean
- Inherited Risk: 2
- Total Siblings: 1
- Active Siblings: 0
- Threat Siblings: 1
- Risk Distribution: High: 0, Medium: 0, Low: 0
## Observation History (14 Records)
Most recent signal observations recorded on 2026-07-31. The IP demonstrates:
- Consistent organizational attribution (SAUDINET-STC)
- Stable geolocation data from multiple sources (MaxMind Geolite2, Cymru)
- Single threat observation with no persistent malicious behavior
- No ownership changes detected
- Threat persistence days: 0
## Relationships
- Same Network: Dammam-Residential-Fixed-Broadband
## Recommended Actions
Based on the moderate risk profile (Score: 50), the following blocking rules are recommended pending contextual validation:
Firewall Rules:
- iptables: `iptables -A INPUT -s 143.92.158.116 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 143.92.158.116 drop`
- nginx: `deny 143.92.158.116;`
- pfSense: `143.92.158.116/32`
- Cloudflare WAF: Block with expression `ip.src eq 143.92.158.116`
- AWS WAF: Address: `143.92.158.116/32`, Description: "IPDebrief risk 50"
Analysis Notes:
The IP is a residential mobile endpoint with no active services. The moderate risk score appears to derive from DNSBL listings rather than active threat indicators. Given the residential nature and lack of service activity, false positive risk is moderate. Review is recommended before implementing blocking measures to avoid disruption to legitimate residential traffic.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | SAUDINET-STC |
| ASN | AS25019 |
| Network Name | Dammam-Residential-Fixed-Broadband |
| CIDR Block | 143.92.144.0/20 |
| RIR | ARIN |
| Country | SA |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 0% | 0 | 0 |
| Overall | 18% | 5 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-30 17:11:24 UTC |
| Last Seen | 2026-08-03 05:13:49 UTC |
| Profile Built | 2026-07-31 03:29:04 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.