# IPDebrief Intelligence Briefing
Target: 188.170.72.2/32
Date: Current Analysis
Classification: Low Risk / Passive
---
## Executive Summary
The IP address 188.170.72.2 belongs to PJSC MegaFon (ASN 31213, Org: GDC-TR-CoreIP) within the 188.170.72.0/21 block registered under RIPE. The IP presents a low-risk profile (Risk Score: 15) with no active threat indicators. No open services are detected, and the address is currently firewalled. Geolocation data indicates Russia (St. Petersburg region), though historical signals show some inconsistency with Moscow references.
---
## Ownership & Network Classification
| Attribute | Value |
|---|---|
| **Organization** | PJSC MegaFon (GDC-TR-CoreIP) |
| **ASN** | AS31213 |
| **CIDR Block** | 188.170.72.0/21 |
| **RIR** | RIPE |
| **Country** | Russia (RU) |
| **City** | St. Petersburg (with historical Moscow signals) |
| **Network Type** | Residential/Enterprise ISP |
Network Role: No active services detected. Port scan analysis returned zero open ports. The IP is classified as firewalled/no services, indicating it is likely a backend or internal endpoint.
---
## Threat Assessment
Overall Risk Score: 15/100 (Low Risk)
Threat Indicators
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Blacklist Count: 0
- Known Campaigns: None identified
- DNSBL Listing: 1 of 8 lists (minimal impact)
Abuse Confidence: Low. The IP shows no correlation to active threat campaigns or known malicious activity patterns.
---
## Behavioral Analysis
Observation History: 12 recorded signals (July 2026)
Key Observations
- Provider attribution consistently identifies GDC-TR-CoreIP via RIPE database
- Geolocation signals show variation between St. Petersburg and Moscow coordinates
- One signal flagged "has_threats" with Pulse count 1 (low confidence: 0.75)
- No persistent malicious behavior observed over the observation window
- No threat persistence indicators
Risk Trend: Stable. No degradation or escalation in observed signals.
---
## Neighborhood Analysis
Subnet: 188.170.72.0/24 (24-bit neighborhood)
- Abuse Density: 0%
- Neighbor Count: 0
- Risk Distribution: No high/medium/low risk neighbors detected
The immediate /24 neighborhood shows minimal activity, suggesting this is not part of a coordinated abuse infrastructure.
---
## Technical Details
| Category | Details |
|---|---|
| **DNS** | No PTR records; forward resolution failed |
| **Email Auth** | No SPF/DMARC records (not configured) |
| **Services** | No open ports; no TLS certificates |
| **Route Stability** | Route changes: 0 in 30 days (stable) |
| **MoAS Status** | Not a Malicious Actor Subnet |
| **RPKI** | State: Not validated |
---
## Recommended Actions
Immediate: No firewall blocks recommended. Risk profile does not warrant aggressive defensive measures.
Monitoring: Standard traffic monitoring appropriate. Consider adding to passive observation list if anomalous behavior emerges.
Investigation Priority: Low. No actionable threat intelligence.
---
## SOC Analyst Notes
- The IP is associated with a major Russian telecommunications provider (MegaFon)
- No open services detected; likely an internal or non-public endpoint
- Historical geolocation inconsistencies warrant attention if forensic accuracy is required
- No immediate threat indicators present
- If this IP is observed in suspicious traffic, investigate context rather than IP alone
Conclusion: This is a low-risk residential/ISP endpoint with no active threat indicators. No immediate action required.
---
*Intel generated by IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | GDC-TR-CoreIP |
| ASN | AS31213 |
| Network Name | MF-NORD-WEST-PS |
| CIDR Block | 188.170.72.0/21 |
| RIR | RIPE |
| Country | RU |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-22 19:32:43 UTC |
| Last Seen | 2026-07-29 14:57:35 UTC |
| Profile Built | 2026-07-29 15:07:59 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.