# IP INTELLIGENCE BRIEFING: 209.99.190.99/32
Date: 2026-07-30
Classification: Moderate Risk Threat Actor / Potential Spam Source
Analyst: IPDebrief Intelligence Team
---
## EXECUTIVE SUMMARY
Target IP 209.99.190.99 presents a moderate risk profile (score: 65/100) with multiple threat indicators. The IP is geolocated to Zurich, Switzerland, but exhibits inconsistent geolocation validation. The address is listed on 3 DNSBLs and is associated with a /24 subnet showing elevated abuse density (11.1%). No active services are detected on the target IP.
---
## RISK ASSESSMENT
| Metric | Value | Assessment |
|---|---|---|
| **Risk Score** | 65/100 | Moderate Risk |
| **Abuse Confidence** | Listed on 3/8 DNSBLs | Elevated |
| **Stability** | 0 | Unstable |
| **Operator Score** | 0.1304 | Minimal |
---
## GEOLOCATION & NETWORK ATTRIBUTES
- Country: Switzerland (CH)
- Region/City: Zurich, Zurich
- Coordinates: 47.36°N, 8.54°E
- ASN: 402253
- BGP Prefix: 209.99.184.0/21
- Service Status: Firewalled / No Services
- DNSSEC: Valid
- Geo Validation: โ ๏ธ Not Plausible
---
## THREAT INDICATORS
- DNSBL Listings: 3 of 8 total lists (listed)
- Known Campaigns: None identified
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Honeypot Hits: 0
- Total Incidents: 0
- Auto-Banned: No
---
## NEIGHBORHOOD ANALYSIS (209.99.190.0/24)
Abuse Density: 11.1% (Elevated)
Total Siblings: 9 IPs analyzed
Notable Neighbor Risk Scores:
- 209.99.190.200: Risk 80 (HIGH) โ ๏ธ
- 209.99.190.113: Risk 65 (HIGH) โ ๏ธ
- 209.99.190.126: Risk 50 (MEDIUM)
- 209.99.190.174: Risk 25 (LOW)
Risk Distribution: 1 High, 3 Medium, 5 Low risk neighbors
---
## OBSERVATION HISTORY
Seven observations recorded through July 30, 2026, showing:
- Consistent Zurich, Switzerland geolocation
- DNSSEC validation present
- DNSBL listings confirmed in recent observations
- Operator score maintained at 0.1304
---
## RELATIONSHIP GRAPH
No relationships identified (0 links to subnets, hostnames, organizations, or certificates).
---
## RECOMMENDED ACTIONS
Primary Recommendation: Increase logging verbosity and review recent activity from this IP source.
Firewall/Blocking Rules:
```bash
# iptables
iptables -A INPUT -s 209.99.190.99 -j DROP
# nftables
nft add rule inet filter input ip saddr 209.99.190.99 drop
# NGINX
deny 209.99.190.99;
# pfSense
209.99.190.99/32
# Cloudflare WAF
Block IP 209.99.190.99 โ IPDebrief risk score 65
# AWS WAF
Addresses: 209.99.190.99/32
Description: IPDebrief risk 65
```
---
## INTELLEIGENCE JUDGMENT
This IP should be blocked or monitored based on:
1. Moderate risk score (65/100)
2. Multiple DNSBL listings indicating prior abuse
3. Neighbor subnet shows 11.1% abuse density with high-risk neighbors
4. Inconsistent geolocation validation
5. No legitimate service indicators
Priority: MEDIUM โ Monitor for increased activity or service changes.
---
*Report generated by IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | SKN Subnet & Telecom Ltd |
| ASN | AS402253 |
| Network Name | SSTL-49 |
| CIDR Block | 209.99.184.0/21 |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Residential |
| Service Purpose | Single-Service Host |
| Network Tier | End-User โ Residential ISP endpoint |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_8.4p1 Debian-5+deb11u6 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-27 03:36:04 UTC |
| Last Seen | 2026-08-02 17:02:23 UTC |
| Profile Built | 2026-07-30 10:44:53 UTC |
| Data Freshness | Live |
| Signal Types | 15 |
| Total Observations | 15 |
Full dossier details are available via our API.