IPDebrief

209.99.190.115

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 209.99.190.115/32

Classification: Moderate Risk Residential Endpoint

Report Date: 2026-07-30

Intel Level: Standard

Assigned Risk Score: 40/100

---

## Executive Summary

IP address 209.99.190.115 is identified as a residential endpoint within the SKN Subnet & Telecom Ltd network (ASN 402253). The IP presents moderate risk (score 40) with evidence of DNS blacklist presence and recent port scanning activity. While not classified as a known attacker or spam source, the IP should be monitored for sustained malicious behavior and considered for blocking in security contexts.

---

## Network Ownership & Geography

FieldData
**Organization**SKN Subnet & Telecom Ltd
**ASN**402253
**CIDR Block**209.99.184.0/21
**Primary Location**Zurich, Switzerland (CH)
**RIR**ARIN
**Abuse Contact**abuse@skntelecom.com

*Note: Historical observations indicate geolocation inconsistencies with Saint Kitts and Nevis references in some probes, suggesting potential routing anomalies or spoofed origin data.*

---

## Threat Assessment

Current Risk Profile:

Observed Services:

---

## Neighborhood Analysis

The /24 subnet (209.99.190.0/24) exhibits moderate abuse density (0.111) with 9 neighboring IPs analyzed:

IP AddressRisk ScoreClassification
209.99.190.20080High Risk
209.99.190.9965Medium-High Risk
209.99.190.11365Medium-High Risk
209.99.190.12650Medium Risk
209.99.190.40, .110, .112, .172, .174, .20025-50Low-Medium Risk

*Subject IP (209.99.190.115) shows risk score 40, positioning it in the medium-risk tier alongside several neighbors.*

---

## Historical Observations

Twelve signals observed through 2026-07-30. Key observations include:

---

## Related Entities

---

## Recommended Actions

Immediate Mitigation:

```bash

# iptables

iptables -A INPUT -s 209.99.190.115 -j DROP

# nftables

nft add rule inet filter input ip saddr 209.99.190.115 drop

# Cloudflare WAF

"ip.src eq 209.99.190.115" โ†’ BLOCK

# AWS WAF

Addresses: ["209.99.190.115/32"]

```

Recommended Policy: Block or rate-limit traffic from this IP given DNSBL presence and moderate risk score. Monitor for correlation with known malicious infrastructure.

---

## Intelligence Notes

This IP represents a residential endpoint with moderate risk characteristics. While not actively malicious per current indicators, the DNSBL presence and neighborhood risk profile suggest caution. SOC analysts should correlate with other signals before definitive blocking decisions. The subnet contains multiple higher-risk neighbors (209.99.190.200, 209.99.190.99, 209.99.190.113) warranting broader subnet-level review.

---

Generated by IPDebrief Intelligence Platform

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡จ๐Ÿ‡ญ Switzerland
RegionZurich
CityZurich
TimezoneEurope/Zurich
Latitude47.36
Longitude8.54

๐Ÿข Ownership & Registration

OrganizationSKN Subnet & Telecom Ltd
ASNAS402253
Network NameSSTL-49
CIDR Block209.99.184.0/21
RIRARIN
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)

๐Ÿ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureResidential
Service PurposeSingle-Service Host
Network TierEnd-User โ€” Residential ISP endpoint
Residential

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
22sshtcp
Closed Ports25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”
SSH VersionSSH-2.0-OpenSSH_8.4p1 Debian-5+deb11u6
โš  Unusual for residential โ€” open services on a home connection may indicate self-hosting, compromise, or misconfigured networking equipment.

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
0%
00
reputation
0%
00
geolocation
0%
00
Overall12%33
Coverage: 3/6 dimensions ยท Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-07-27 03:36:04 UTC
Last Seen2026-07-30 10:34:49 UTC
Profile Built2026-07-30 10:44:53 UTC
Data FreshnessLive
Signal Types15
Total Observations15
๐Ÿ” 15 signal types ยท 15 observations collected
This report is generated from 15+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.