# IP Intelligence Briefing: 199.91.128.98/32
## Executive Summary
Intellect analysis of 199.91.128.98 indicates a moderate risk residential network endpoint with no active threat indicators. The IP belongs to Peetz Telephone's 199.91.128.0/23 block in Colorado and shows no evidence of malicious activity despite minor DNSBL presence.
## Threat Profile
Risk Assessment: Moderate (Score: 55/100)
- DNSBL Status: Listed on 3 of 8 DNSBL feeds (dnsblListedCount: 3)
- Threat Indicators: None detected. IP is not a known attacker, spam source, Tor exit node, or proxy
- Abuse Confidence: No abuse confidence score generated; no known campaigns associated
- Malicious Persistence: Threat observation count: 0; not persistently malicious
## Network Infrastructure
| Attribute | Value |
|---|---|
| ASN | 32281 |
| Organization | Peetz Telephone |
| Netname | PEETZ-NET1 |
| CIDR Block | 199.91.128.0/23 |
| RIR | ARIN |
| Location | United States, Colorado, Peetz |
| Service Status | Firewalled / No Services |
| Open Ports | None detected |
## Network Neighborhood Analysis
Subnet: 199.91.128.98/24
- Abuse Density: 0%
- Neighbor Count: 0 siblings detected
- Risk Distribution: No high/medium/low risk neighbors observed
- Classification: No inherited risk from subnet
## Control Plane & Routing
- Route Stability: Not stable (route changes detected)
- BGP Origin: 199.91.128.0/23
- DNSSEC: Valid
- Transit Networks: Comcast, Cogent
- Traceroute: 16 hops; first hop RTT: 0.2ms; last hop RTT: 63.2ms; 1 timed-out hop
## Historical Observations
Total Signals: 12 observations
Recent signal types observed:
- Traceroute analysis (confidence: 85%)
- Ownership verification (confidence: 90%)
- Network classification (confidence: 30%)
- Organization registration (confidence: 95%)
No evidence of escalating threat behavior or ownership changes over observation period.
## Relationship Graph
- Direct Relationships: 4 relationships identified
- Target Type: All relationships map to same network (PEETZ-NET1)
- External Connections: No hostnames, certificates, or organizational relationships detected
## Recommended Actions
Firewall Rules
```
# Block if positive security findings emerge
iptables -A INPUT -s 199.91.128.98 -j DROP
```
Monitoring Recommendations
- Monitor for DNSBL listing changes (currently 3 of 8 lists)
- Track for any service port openings (currently firewalled)
- No immediate action required; standard residential IP monitoring recommended
## Intelligence Assessment
199.91.128.98 represents a residential network endpoint with moderate risk classification primarily due to DNSBL presence. No active threat intelligence correlates detected. The IP lacks service ports, shows no malicious campaign associations, and operates within a low-abuse-density subnet. SOC teams may apply standard monitoring; no immediate blocking recommended unless additional threat indicators emerge.
---
*Report generated: Based on IPDebrief intelligence platform data*
*Classification: Unverified Threat Intelligence*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Peetz Telephone |
| ASN | AS32281 |
| Network Name | PEETZ-NET1 |
| CIDR Block | 199.91.128.0/23 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 22 | ssh | tcp | β |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | lighttpd/1.4.54 |
| HTTP Title | β |
π TLS Certificate
| SANs | UBNT-24:5A:4C:B0:49:CC |
| Valid From | 2019-01-01T00:00:00+00:00 |
| Valid Until | 2038-01-01T00:00:00+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 6940 days |
| Serial Number | 9CD877DD |
| Thumbprint | 3A60484814EAC8D8D8B103768EE2D262DBEA4BFD |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 8% | 2 | 2 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-25 02:41:46 UTC |
| Last Seen | 2026-08-06 00:36:00 UTC |
| Profile Built | 2026-08-04 12:17:20 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 19 |
Full dossier details are available via our API.