IPDebrief

149.233.211.25

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

## INTELLIGENCE BRIEFING: 149.233.211.25/32

Classification: Low Risk / Residential Broadband

Date: Current

Analyst: IPDebrief Intelligence Team

---

EXECUTIVE SUMMARY

IP 149.233.211.25 is a residential broadband endpoint classified as low risk (Risk Score: 25). The address belongs to a private PPPoE customer network operated by WTNET (ASN 15943), a German ISP. No active malicious indicators detected. One DNSBL listing identified. Geolocation data shows conflicting country assignments requiring validation.

---

NETWORK OWNERSHIP & CLASSIFICATION

---

GEOLOCATION ANALYSIS

Primary Assignment: United States (Boston, MA)

Secondary Assignment: Germany (Hamburg, Free and Hanseatic City of Hamburg)

Discrepancy Note: Geolocation data sources are inconsistent. Profile data indicates US assignment, while historical observations show Germany. This geographic conflict warrants additional validation. Multiple geo sources (geoSourceCount: 2) with geoConsensus: false indicates low confidence in location accuracy.

Routing Path: Originates through Comcast and additional transit networks (12 hops total)

---

THREAT INDICATORS

IndicatorStatus
Is Known AttackerNo
Is Tor Exit NodeNo
Is Spam SourceNo
Blacklist Count1 of 8 DNSBL lists
Active Threat CampaignsNone
Pulsedive RiskNot Available

DNSBL Status: Listed on 1 of 8 blacklist sources (Max Severity: High per historical observation)

---

OBSERVATION HISTORY (15 Signals)

Recent signal activity shows variable confidence levels (0.17–0.85):

Threat Persistence: 0 days observed. IP is not persistently malicious.

---

NETWORK RELATIONSHIPS

---

SUBNET ANALYSIS (149.233.211.0/24)

---

SECURITY ACTIONS & RECOMMENDATIONS

Current Risk Score: 25 (Low Risk)

Recommended Actions: None generated by automated analysis

Firewall Rules: Not applicable (no active services detected)

Assessment: No immediate blocking or filtering required. However, the DNSBL listing and geolocation discrepancy warrant monitoring.

---

INTELLIGENCE ASSESSMENT

Threat Level: LOW

Primary Concern: DNSBL listing (1 of 8 lists) with high severity classification in historical data, though current profile shows no active threat indicators.

Key Findings:

1. Residential endpoint with dynamic PPPoE hostname (typical consumer broadband)

2. No open ports or active services (firewalled configuration)

3. Clean subnet environment with zero abuse density

4. Geolocation inconsistency requires validation

5. No correlation to known malicious campaigns or related threat infrastructure

Recommendation: Monitor for DNSBL listing persistence. If high-severity listing persists beyond 7 days, consider enhanced monitoring. No immediate containment actions required.

---

END OF BRIEFING

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇩🇪 Germany
RegionFree and Hanseatic City of Hamburg
CityHamburg
TimezoneEurope/Berlin
Latitude51.17
Longitude10.45

🏢 Ownership & Registration

OrganizationNORDERSTEDT-MNT
ASNAS15943
Network NameWT-PPPOE-PRIVATE-CUSTOMER-NET
CIDR Block149.233.192.0/19
RIRARIN
CountryDE
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR149.233.211.25.dynamic-pppoe.dt.ipv4.wtnet.de
Forward ConfirmedYes — FCrDNS verified
Forward Hostnames149.233.211.25.dynamic-pppoe.dt.ipv4.wtnet.de

🔐 DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierTier 3 — Basic operator with some routing infrastructure
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Server—
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS15943
Network Prefix149.233.128.0/17
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
17%
23
routing
8%
11
services
12%
22
ownership
17%
23
reputation
8%
12
geolocation
17%
23
Overall13%1014
Coverage: 4/6 dimensions · Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

📅 Observation Timeline 🔄 Live

First Seen2026-07-19 18:09:16 UTC
Last Seen2026-09-03 16:05:22 UTC
Profile Built2026-09-03 16:14:25 UTC
Data FreshnessLive
Signal Types23
Total Observations31
🔍 23 signal types · 31 observations collected
This report is generated from 23+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 149.233.211.25

Who owns the IP address 149.233.211.25?

149.233.211.25 is registered to NORDERSTEDT-MNT. The address falls within the 149.233.192.0/19 network block. Registration is held at ARIN.

Where is 149.233.211.25 located?

Geolocation data places 149.233.211.25 in Hamburg, Free and Hanseatic City of Hamburg, Germany. The local time zone is Europe/Berlin. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 149.233.211.25 malicious or safe?

149.233.211.25 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.

What is the hostname for 149.233.211.25?

The reverse DNS (PTR) record for 149.233.211.25 is 149.233.211.25.dynamic-pppoe.dt.ipv4.wtnet.de. This hostname is forward-confirmed, meaning it resolves back to the same address.

🏘️ Related IP Addresses

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.