IPDebrief

188.90.104.164

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# INTELLIGENCE BRIEFING: 188.90.104.164

Classification: Low Risk | Risk Score: 25 | Analysis Date: 2026-06-05

---

## EXECUTIVE SUMMARY

IP address 188.90.104.164 was analyzed as a residential fiber-to-the-home (FTTH) connection associated with Dutch ISP Odido (Access & transport, ASN 50266). The address exhibits low-risk characteristics with a score of 25/100, though historical signals indicate prior threat activity. No active services or open ports were detected during observation.

---

## NETWORK OWNERSHIP AND GEOLOCATION

The IP address is registered to Odido Netherlands B.V. (ASN 50266), a RIPE RIR-registered organization operating from the Netherlands. Geolocation data placed the address in Koudekerke, Zeeland region, NL, with coordinates 52.13°N, 5.29°E and 150km accuracy radius. Multiple geo-validation sources corroborated the Netherlands attribution. The address resolved via reverse DNS to 164-104-90-188.ftth.glasoperator.nl, confirming residential broadband assignment.

---

## NETWORK ROLE AND CLASSIFICATION

Analysis indicated the address was firewalled with no active services exposed. The address is not classified as cloud, CDN, VPN, proxy, Tor exit node, hosting infrastructure, mobile carrier, or anycast. The BGP prefix 188.90.0.0/16 originated from ASN 50266 with route stability marked as false. DNSSEC validation was confirmed as valid.

---

## THREAT INTELLIGENCE

Current threat assessment shows no active indicators of compromise. The IP is not flagged as a known attacker, spam source, or Tor exit node. Blacklist enumeration returned zero current listings. However, historical signal observations from 2026-06-05 showed elevated threat indicators including `has_threats: true` with a pulse count of 2 across multiple threat feeds. The address carried one DNSBL listing among eight total lists scanned.

---

## DNS AND EMAIL REPUTATION

Forward DNS resolution confirmed with one PTR hostname. Email authentication configuration included SPF records but lacked DMARC implementation. TXT record count was zero. No hosted domains or email authentication failures were observed.

---

## NEIGHBORHOOD ANALYSIS

The /24 subnet (188.90.104.164/24) showed abuse density of 1 with classification marked "mostly_clean." One threat-sibling IP was identified within the subnet, while the remaining sibling addresses showed zero active threats. The subnet risk distribution showed high, medium, and low categories all at zero active threats during this observation window.

---

## OBSERVATION HISTORY

Eighteen total signal observations were recorded as of 2026-06-05. Recent observations consistently attributed the address to Odido Netherlands B.V. and confirmed NL geolocation. Multiple signal sources (AlienVault OTX, Cymru, multiple inference engines) provided corroborating data. Operator score remained at 0.2609 (Basic classification).

---

## RECOMMENDED ACTIONS

Based on the low-risk profile (score 25) and residential broadband classification:

1. Allow with monitoring โ€“ Traffic from this address may be permitted through existing firewalls with logging enabled

2. No blocking required โ€“ Current threat indicators do not warrant blocking at perimeter

3. Monitor historical threat signals โ€“ Review the two prior threat pulses for correlation with any incidents

4. Email policy consideration โ€“ Address lacks DMARC; evaluate whether to block or allow based on email reputation requirements

---

Analyst Notes: This address represents a residential consumer connection. The low risk score and absence of active services suggest benign end-user traffic. The historical threat signals warrant awareness but do not indicate current malicious activity.

End of Briefing

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ณ๐Ÿ‡ฑ Netherlands
RegionZE
CityKoudekerke
TimezoneEurope/Amsterdam
Latitude52.13
Longitude5.29

๐Ÿข Ownership & Registration

OrganizationAccess & transport
ASNAS50266
Network Nameโ€”
CIDR Blockโ€”
RIRRIPE
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR164-104-90-188.ftth.glasoperator.nl
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnames164-104-90-188.ftth.glasoperator.nl

๐Ÿ” DNS Hygiene

Hygiene Score60% (Good)
SPFPresent
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown โ€” Insufficient routing data to classify
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
24%
23
routing
13%
11
services
8%
11
ownership
27%
23
reputation
22%
13
geolocation
19%
22
Overall19%913
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-09 11:33:46 UTC
Last Seen2026-06-25 15:44:34 UTC
Profile Built2026-06-25 15:51:01 UTC
Data FreshnessLive
Signal Types20
Total Observations21
๐Ÿ” 20 signal types ยท 21 observations collected
This report is generated from 20+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.