## IP Intelligence Briefing: 153.52.117.249/32
Classification: Low Risk / No Active Threat Indicators
Analysis Date: Current
---
**Executive Summary**
IP 153.52.117.249 presents as a low-risk address with no active threat indicators, no services detected, and no malicious activity observed in available intelligence feeds. The address is assigned to organization VEKTOR-AITI-TEKHNOLOGII (ASN 209378) under RIR APNIC.
---
**Network Attribution**
- Organization: VEKTOR-AITI-TEKHNOLOGII (interlir-mnt)
- ASN: 209378
- CIDR Block: 153.52.117.0/24
- RIR Registration: APNIC
- Abuse Contact: Available via RDAP
---
**Geolocation Analysis**
- Country Code: DE (Germany)
- Reported City: Russian Federation
- Coordinates: 51.17°N, 10.45°E
- GeoConsensus: False (multiple sources show conflicting data)
- Note: Geolocation data shows inconsistency between country code and city attribution.
---
**Threat Intelligence Profile**
| Metric | Value |
|---|---|
| Risk Score | 0 (Low Risk) |
| Abuse Confidence | None |
| Blacklist Count | 0 |
| Threat Feeds | None |
| Is Tor Exit | False |
| Is Known Attacker | False |
| Is Spam Source | False |
- Network Role: Firewalled / No Services Detected
- Open Ports: None
- DNS Records: No PTR hostnames, no forward resolution
- Email Authentication: No SPF or DMARC configured
---
**Subnet Neighborhood Assessment**
- Subnet: 153.52.117.0/24
- Abuse Density: 0.0 (Clean)
- Threat Siblings: 0
- Active Siblings: 0
- Total Siblings: 1
The /24 subnet exhibits no abuse activity or neighboring threat indicators.
---
**Historical Signal Analysis**
12 observations retrieved from 2026-07-25:
- Ownership Changes: 0
- Threat Persistence: 0 days
- Persistent Malicious Activity: False
- Operator Score: 0.1304 (Minimal)
*Note: One historical signal indicated conflicting ASN attribution (AS14962 ncr corporation, US), but current profile confirms ASN 209378.*
---
**Entity Relationships**
- Network Associations: VEKTOR-AITI-TEKHNOLOGII (2x same network entries)
- External Entity Links: None detected
- Certificate Associations: None
---
**Recommended Actions**
No blocking or filtering actions recommended. The IP address:
- Shows no active threat indicators
- Has no services or open ports
- Belongs to a clean subnet with zero abuse density
- Is not listed on threat feeds or blacklists
Monitoring Recommendation: Standard passive monitoring only. No immediate threat response required.
---
**Intelligence Assessment**
This IP address represents minimal threat to defensive security operations. The absence of services, combined with zero abuse density in the /24 subnet and no threat feed listings, indicates legitimate or dormant infrastructure. Geolocation inconsistencies warrant periodic verification but do not indicate malicious activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | interlir-mnt |
| ASN | AS209378 |
| Network Name | VEKTOR-AITI-TEKHNOLOGII |
| CIDR Block | 153.52.117.0/24 |
| RIR | APNIC |
| Country | FI |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS209378 |
| Network Prefix | 153.52.117.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 20% | 5 | 6 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-09 01:18:44 UTC |
| Last Seen | 2026-08-27 02:43:14 UTC |
| Profile Built | 2026-08-29 06:25:05 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 19 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 153.52.117.249
Who owns the IP address 153.52.117.249?
153.52.117.249 is registered to interlir-mnt. The address falls within the 153.52.117.0/24 network block. Registration is held at APNIC.
Where is 153.52.117.249 located?
Geolocation data places 153.52.117.249 in Germany. The local time zone is Europe/Berlin. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 153.52.117.249 malicious or safe?
153.52.117.249 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 153.52.117.249?
Responsive ports observed on 153.52.117.249 include 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.