# IP Intelligence Briefing: 2.48.94.9
Classification: Moderate Risk | Date: 2026-07-30
## Executive Summary
IP 2.48.94.9 is a telecommunications infrastructure address operated by ETISALAT (EMIRATES TELECOMMUNICATIONS GROUP) under ASN 5384. The address demonstrates moderate risk due to DNSBL listings (2 of 8 lists) but shows no active malicious service indicators. Network infrastructure suggests legitimate carrier operations with firewalled status.
## Network Infrastructure
- ASN: 5384 (EMIRATES-INTERNET)
- Organization: EMIRATES TELECOMMUNICATIONS GROUP COMPANY PJSC, AE
- CIDR Block: 2.48.0.0/16
- Geolocation: Marseille, France (FR) โ with origin registration in UAE (AE)
- BGP Prefix: 2.48.64.0/18
- Status: Firewalled / No Services Open
- Route Stability: Unstable
## Threat Assessment
- Risk Score: 50 (Moderate)
- DNSBL Listings: 2 active listings across 8 total blacklists
- Maximum Severity: High
- Tor Exit/Proxy: False
- Known Attacker: False
- Abuse Confidence: Not quantified
## Service & DNS Analysis
- Open Ports: None detected
- DNSSEC: Valid
- PTR Records: None
- Forward Resolution: Failed
- Email Authentication: SPF/DMARC not configured (no hosted domains)
- SSL/TLS: None observed
## Behavioral Indicators
- Honeypot Hits: 0
- WAF Violations: 0
- Enumeration Strikes: 0
- Total Incidents: 0
- Threat Persistence: None observed
## Neighborhood Context
Subnet 2.48.94.0/24 analyzed:
- Total Siblings: 1
- Abuse Density: 0
- Neighbor IP: 2.48.94.112 (Risk Score: 25, Authority: 50)
- Classification: Low risk sibling profile
## Historical Trends (13 Observations)
- Ownership Changes: 0
- DNSSEC Validity: Confirmed
- ASN Consistency: ASN 5384 confirmed across observations
- Listings: Recent blacklist activity with high severity designation
- Geolocation: Consistent France/UAE split
## SOC Recommendations
1. Monitor DNSBL Activity: Address is listed on 2 blacklists; monitor for additional takedowns
2. Low Immediate Action Required: No active service exploitation or attack patterns detected
3. Network Context: Legitimate telecommunications carrier infrastructure; false positive potential
4. Geolocation Discrepancy: Note France geolocation vs. UAE ASN registration โ standard for international carrier routing
5. Neighbor Monitoring: Single sibling IP (2.48.94.112) maintains low risk posture
## Conclusion
IP 2.48.94.9 represents a legitimate telecommunications carrier address with moderate risk classification primarily driven by DNSBL listings. No active exploitation or attack indicators present. Recommend monitoring but no immediate blocking or defensive action required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | ETISALAT-MNT |
| ASN | AS5384 |
| Network Name | GPRS-EMIRNET |
| CIDR Block | 2.48.0.0/16 |
| RIR | RIPE |
| Country | AE |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 4% | 1 | 2 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-24 20:34:04 UTC |
| Last Seen | 2026-08-04 11:50:58 UTC |
| Profile Built | 2026-07-30 01:14:26 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.