# IP Intelligence Briefing: 188.253.209.191/32
Date: 2026-07-29
Classification: Moderate Risk (Score: 40/100)
Origin: AZTELEKOM-ISP, Azerbaijan (Baku City)
---
## Executive Summary
IP 188.253.209.191 is a moderately risky address assigned to AZTELEKOM-ISP (ASN 28787) in Azerbaijan. The IP is currently firewalled with no active services, no open ports, and no DNS forward resolution. While it shows no direct threat indicators (not a known attacker, proxy, Tor exit, or spam source), it is listed on 2 out of 8 DNSBLs. The IP demonstrates network instability with 12 observation records showing recent activity.
---
## Technical Profile
Ownership & Network:
- Organization: AZTELEKOM-ISP (Aydamir Aydamirov)
- ASN: 28787 (AS-AZTELEKOM - Aztelekom LLC, AZ)
- CIDR Block: 188.253.128.0/18
- BGP Prefix: 188.253.208.0/22
- Registration Date: 2011-02-10 (via team-cymru-dns)
- Route Stability: Unstable (isRouteStable: false)
- RRPKI State: Not evaluated
Geolocation:
- Country: Azerbaijan (AZ)
- City: Baku City
- Coordinates: 40.38°N, 49.89°E
- Geo Validation: Inconsistent (geoPlausible: false)
- Traceroute: 30 hops, 15 timed out, transit via Comcast
DNS & Services:
- PTR Records: None
- Forward Resolution: Not confirmed
- Hosted Domains: 0
- Email Auth (SPF/DMARC): Not configured
- Open Ports: None (firewalled)
- TLS/HTTP Services: None detected
---
## Threat Assessment
Risk Indicators:
- Risk Score: 40 (Moderate)
- Blacklist Status: Listed on 2 of 8 DNSBLs (max severity: high)
- Threat Feeds: Empty
- Known Campaigns: None correlated
- Tor/VPN/Proxy: Not identified
- Attacker Status: Not flagged as known attacker
Behavioral Indicators:
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: 0
- Total Incidents: 0
- Auto-Banned: No
Historical Activity:
- Observation Count: 12 signals recorded
- Recent Activity: 2026-07-29T08:51:29 UTC
- Ownership Changes: 0
- Threat Persistence: 0 days
- Persistent Malicious Activity: No
---
## Network Neighborhood Analysis
Subnet: 188.253.209.0/24
Total Neighbors: 6 IPs
Abuse Density: 0 (Low)
Risk Distribution: 0 High, 0 Medium, 3 Low
Notable Neighbors:
| IP Address | Risk Score | Authority Score |
|---|---|---|
| 188.253.209.54 | 15 | 50 |
| 188.253.209.237 | 15 | 50 |
| 188.253.209.239 | 15 | 50 |
The subnet shows minimal abuse density with most neighbors having low risk profiles. No high-risk activity detected in immediate vicinity.
---
## Relationships
Connected Entities: 3 relationships identified
- All classified as "Same Network" to AZTELEKOM-ISP
- No hostnames, organizations, or certificates directly correlated
---
## Recommended Actions
Firewall Rules:
- Monitor but do not block (Moderate Risk)
- Consider rate limiting if outbound traffic patterns change
- No immediate blocking recommended
Investigation Priorities:
- Monitor DNSBL listing status (2/8 lists active)
- Track route stability improvements
- Watch for service activation on previously firewalled IP
Threat Indicators:
- No immediate threat indicators present
- No certificate or hostname correlations
- No known malicious campaigns associated
---
## Conclusion
IP 188.253.209.191 presents a moderate risk profile with no active threat indicators. The address is firewalled, unresponsive to service probes, and shows no evidence of malicious activity. The 2/8 DNSBL listing warrants monitoring but does not currently justify blocking. The subnet environment is relatively quiet with low abuse density. SOC teams should maintain standard monitoring practices without aggressive mitigation measures.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Aydamir Aydamirov |
| ASN | AS28787 |
| Network Name | AZTELEKOM-ISP |
| CIDR Block | 188.253.128.0/18 |
| RIR | RIPE |
| Country | AZ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 4% | 1 | 2 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-21 12:55:09 UTC |
| Last Seen | 2026-07-29 08:47:56 UTC |
| Profile Built | 2026-07-29 09:01:29 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 16 |
Full dossier details are available via our API.