# IP Intelligence Briefing: 212.204.187.122/32
Classification: Residential Cable Connection โ Netherlands
Date: 2026-06-25
Risk Assessment: Low Risk (Score: 25/100)
---
## Executive Summary
IP 212.204.187.122 is a residential cable connection hosted by VODAFONEZIGGO IP AUTHORITY (ASN 33915) in Zandvoort, North Holland, Netherlands. The IP presents as a low-risk residential endpoint with no active malicious indicators, no known campaign associations, and a clean subnet reputation. No immediate defensive action required, though monitoring is recommended due to historical blacklist activity.
---
## Technical Profile
Ownership & Registration:
- Organization: VODAFONEZIGGO IP AUTHORITY
- ASN: 33915
- BGP Prefix: 212.204.160.0/19
- RIR: RIPE
- Network Classification: Residential Cable (Dynamic IP)
Geolocation:
- Country: Netherlands (NL)
- Region: North Holland
- City: Zandvoort
- Coordinates: 52.13°N, 5.29°E
- Geo Confidence: 1 source, consensus confirmed
DNS & Host Resolution:
- PTR Hostname: 212-204-187-122.cable.dynamic.v4.ziggo.nl
- Forward Resolution: Confirmed (ziggo.nl domain)
- Email Auth: SPF and DMARC records present
- DNSSEC: Valid
- CAA Records: Present
Services:
- Open Ports: None detected
- HTTP/TLS: No services responding
- Status: Firewalled / No Services
---
## Threat Intelligence
Current Threat Status:
- Risk Score: 25/100 (Low Risk)
- Abuse Confidence: Not applicable
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Blacklist Status: Listed on 1 of 8 DNSBL sources (historical)
Threat Indicators:
- No active threat feeds matched
- No known attack campaigns correlated
- No certificate anomalies detected
- No malicious banner matches
---
## Network Behavior & History
Observation History (28 signals):
- Most recent activity: 2026-06-25
- Subnet abuse density: 0 (Clean)
- Threat observation count: 1 (historical)
- Threat persistence: Not persistently malicious
- Ownership changes: None observed
Route Stability:
- Route changes (30-day): 0
- Route stability: Unstable
- Transit networks: Comcast (via traceroute)
- Hop count: 15
Neighbor Analysis (212.204.187.0/24):
- Total siblings: 1
- Active siblings: 1
- Threat siblings: 0
- Abuse density: 0 (Clean subnet)
---
## Relationships
Identified Associations (50 total):
- Network: ZIGGO-CM (same network)
- DNS Hostnames: 212-204-187-122.cable.dynamic.v4.ziggo.nl (primary association)
- No organizational or certificate relationships detected
---
## Recommended Actions
Immediate Actions: None required
Monitoring Recommendations:
- Standard passive monitoring appropriate
- No firewall rules recommended (risk score below threshold)
- No blocking required based on current profile
Decision Matrix:
- Block: Not recommended
- Monitor: Recommended (standard residential IP)
- Allow: Standard policy
---
## Analyst Notes
This IP represents a typical residential broadband connection with dynamic addressing. The historical blacklist presence (1/8 lists) appears to be legacy or low-severity and does not indicate current malicious activity. The subnet shows no abuse density, suggesting the IP was not involved in coordinated attacks. No action beyond standard residential IP handling is warranted at this time.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | VODAFONEZIGGO IP AUTHORITY |
| ASN | AS33915 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 212-204-187-122.cable.dynamic.v4.ziggo.nl |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | 212-204-187-122.cable.dynamic.v4.ziggo.nl |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 19% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 18% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-08 23:18:28 UTC |
| Last Seen | 2026-06-26 18:11:07 UTC |
| Profile Built | 2026-06-25 11:54:00 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 22 |
Full dossier details are available via our API.