IPDebrief

2.89.131.199

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

IP Threat Intelligence Briefing: 2.89.131.199

Date: 2026-06-08

---

**1. Core Profile**

- ASN: 25019

- Organization: SAUDINET-STC (Saudi Telecom Company)

- CIDR: 2.89.0.0/16

- Country: Saudi Arabia (SA)

- Region: Eastern Province

- City: Dammam

- Coordinates: Unknown (null)

- Mobile Carrier: STC (LTE/5G)

- Infrastructure: Firewalled / No Services

---

**2. Threat Indicators**

- No open ports, TLS certs, or HTTP services identified.

- No SPF/DKIM email auth configured.

- AS Path: 25019 (SAUDINETSTC-AS)

- Route Stability: Unstable (route changes detected).

---

**3. Observation History**

- Low-confidence geolocation inferred (Dammam, SA).

- Minimal operator risk score (0.13).

- No persistent threat observations.

---

**4. Network Relationships**

- Associated with SAUDINET_DSL_POOL (same network).

---

**5. Recommended Actions**

- Increase logging verbosity for this IP due to moderate risk.

- Validate geolocation context (Saudi Arabia, mobile carrier).

- iptables: `iptables -A INPUT -s 2.89.131.199 -j DROP`

- Cloudflare WAF: Block IP with rule: `ip.src eq 2.89.131.199`

- AWS WAF: Add `2.89.131.199/32` to IP set.

---

**6. Summary**

The IP 2.89.131.199 is associated with Saudi Telecom Company (STC) and operates as a mobile LTE/5G network. While no direct malicious activity is detected, its moderate risk score and lack of service visibility warrant monitoring. SOC teams should validate geolocation context and consider blocking the IP if it persists in traffic. No immediate action is required, but ongoing observation is advised.

Product: IPDebrief | Copyright: © 2026 Jason Alberino. All rights reserved.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΈπŸ‡¦ SA
RegionEastern Province
CityDammam
TimezoneAsia/Riyadh
Latitude26.43
Longitude50.11

🏒 Ownership & Registration

OrganizationSAUDINET-STC
ASNAS25019
Network NameSAUDINET_DSL_POOL
CIDR Block2.89.0.0/16
RIRRIPE
CountrySA
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)

πŸ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureMobile
Service PurposeFirewalled / No Services
Network TierUnknown β€” Insufficient routing data to classify
Mobile

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
43%
24
routing
17%
11
services
13%
11
ownership
27%
23
reputation
20%
12
geolocation
21%
22
Overall24%913
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-19 09:37:13 UTC
Last Seen2026-06-13 03:45:24 UTC
Profile Built2026-06-13 03:38:55 UTC
Data FreshnessLive
Signal Types16
Total Observations21
πŸ” 16 signal types Β· 21 observations collected
This report is generated from 16+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.