# IP Intelligence Briefing: 209.99.190.115/32
Classification: Moderate Risk Residential Endpoint
Report Date: 2026-07-30
Intel Level: Standard
Assigned Risk Score: 40/100
---
## Executive Summary
IP address 209.99.190.115 is identified as a residential endpoint within the SKN Subnet & Telecom Ltd network (ASN 402253). The IP presents moderate risk (score 40) with evidence of DNS blacklist presence and recent port scanning activity. While not classified as a known attacker or spam source, the IP should be monitored for sustained malicious behavior and considered for blocking in security contexts.
---
## Network Ownership & Geography
| Field | Data |
|---|---|
| **Organization** | SKN Subnet & Telecom Ltd |
| **ASN** | 402253 |
| **CIDR Block** | 209.99.184.0/21 |
| **Primary Location** | Zurich, Switzerland (CH) |
| **RIR** | ARIN |
| **Abuse Contact** | abuse@skntelecom.com |
*Note: Historical observations indicate geolocation inconsistencies with Saint Kitts and Nevis references in some probes, suggesting potential routing anomalies or spoofed origin data.*
---
## Threat Assessment
Current Risk Profile:
- Risk Score: 40 (Moderate)
- DNSBL Listed: 2 of 8 lists
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Active Campaigns: None identified
Observed Services:
- SSH (OpenSSH 8.4p1 Debian-5+deb11u6)
- Multiple port scans detected during recent observation window (2026-07-30)
---
## Neighborhood Analysis
The /24 subnet (209.99.190.0/24) exhibits moderate abuse density (0.111) with 9 neighboring IPs analyzed:
| IP Address | Risk Score | Classification |
|---|---|---|
| 209.99.190.200 | 80 | High Risk |
| 209.99.190.99 | 65 | Medium-High Risk |
| 209.99.190.113 | 65 | Medium-High Risk |
| 209.99.190.126 | 50 | Medium Risk |
| 209.99.190.40, .110, .112, .172, .174, .200 | 25-50 | Low-Medium Risk |
*Subject IP (209.99.190.115) shows risk score 40, positioning it in the medium-risk tier alongside several neighbors.*
---
## Historical Observations
Twelve signals observed through 2026-07-30. Key observations include:
- SSH service detection with OpenSSH 8.4p1 Debian variant
- Multiple port scanning events
- Consistent residential network classification
- No persistent malicious behavior detected over observation period
---
## Related Entities
- Network: SSTL-49 (same /21 block)
- Correlated IPs: None beyond network relationships
---
## Recommended Actions
Immediate Mitigation:
```bash
# iptables
iptables -A INPUT -s 209.99.190.115 -j DROP
# nftables
nft add rule inet filter input ip saddr 209.99.190.115 drop
# Cloudflare WAF
"ip.src eq 209.99.190.115" โ BLOCK
# AWS WAF
Addresses: ["209.99.190.115/32"]
```
Recommended Policy: Block or rate-limit traffic from this IP given DNSBL presence and moderate risk score. Monitor for correlation with known malicious infrastructure.
---
## Intelligence Notes
This IP represents a residential endpoint with moderate risk characteristics. While not actively malicious per current indicators, the DNSBL presence and neighborhood risk profile suggest caution. SOC analysts should correlate with other signals before definitive blocking decisions. The subnet contains multiple higher-risk neighbors (209.99.190.200, 209.99.190.99, 209.99.190.113) warranting broader subnet-level review.
---
Generated by IPDebrief Intelligence Platform
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | SKN Subnet & Telecom Ltd |
| ASN | AS402253 |
| Network Name | SSTL-49 |
| CIDR Block | 209.99.184.0/21 |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Residential |
| Service Purpose | Single-Service Host |
| Network Tier | End-User โ Residential ISP endpoint |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_8.4p1 Debian-5+deb11u6 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-27 03:36:04 UTC |
| Last Seen | 2026-07-30 10:34:49 UTC |
| Profile Built | 2026-07-30 10:44:53 UTC |
| Data Freshness | Live |
| Signal Types | 15 |
| Total Observations | 15 |
Full dossier details are available via our API.