## IP INTELLIGENCE BRIEFING: 212.90.21.58/32
EXECUTIVE SUMMARY
The IP address 212.90.21.58 is classified as LOW RISK with an overall risk score of 15/100. This is a cloud infrastructure endpoint belonging to CLOUDITALIA (ASN 3302) operating under Retelit Contact Role. The IP demonstrates clean security posture with no active threat indicators.
INFRASTRUCTURE PROFILE
- Organization: Retelit Contact Role (CLOUDITALIA)
- ASN: 3302 (RIR: RIPE)
- Network Block: 212.90.16.0/20
- Geolocation: Milan, Italy (Tuscany region)
- Classification: Cloud Infrastructure
- Service Status: Firewalled / No Services Detected
- DNS Resolution: ip-21-58.sn-212-90.clouditalia.com
THREAT INDICATORS ASSESSMENT
Current Threat Status: NONE
- Known Campaigns: No associations
- Attacker Reputation: Not flagged as known attacker
- Tor Exit Node: Not a Tor exit node
- Spam Source: Not identified as spam origin
- Blacklist Status: 0 blacklist hits (minor DNSBL listing detected on 1 of 8 queried lists)
- Abuse Confidence Score: Not applicable (clean profile)
NETWORK CLASSIFICATION
- Provider/Infrastructure: Cloud hosting environment
- Connection Type: Enterprise cloud infrastructure
- Network Role: Not a proxy, VPN, or residential IP
- Mobile Carrier: Not applicable
- Bogon Status: Not a bogon prefix
OBSERVATION HISTORY ANALYSIS
Signal Persistence: 17 historical observations tracked
- Most Recent: 2026-07-24T05:46:20 UTC
- Geolocation Consistency: Italian origin consistently identified (Milan area, Tuscany region)
- Ownership Stability: No ownership changes observed
- Threat Persistence: 0 threat persistence days (no persistent malicious activity)
- Risk Trend: Stable, low-risk profile maintained over observation period
RELATIONSHIP ANALYSIS
The IP maintains standard DNS and network associations:
- DNS Associations: ip-21-58.sn-212-90.clouditalia.com
- Network Affiliation: CLOUDITALIA infrastructure
- No Correlated Malicious Entities: No relationship links to known malicious infrastructure
NEIGHBORHOOD ANALYSIS
Subnet: 212.90.21.58/24
- Abuse Density: 0 (clean)
- Classification: Clean
- Threat Siblings: 0
- Active Siblings: 0
- Total Neighbors Analyzed: 0
CONTROL PLANE DATA
- Origin ASN: 3302
- BGP Prefix: 212.90.0.0/19
- Route Stability: Not stable (route changes observed in 30-day window)
- RPKI State: Not validated
- DNSSEC: Valid
- Hop Count: 14 (standard for Italian infrastructure)
ACTIONABLE INTELLIGENCE FOR SOC
Assessment: LOW PRIORITY MONITORING REQUIRED
This IP represents legitimate cloud infrastructure with no active threat indicators. The firewall configuration and absence of open services limit exposure. No immediate blocking or mitigation actions are recommended.
Recommended Actions:
- Monitoring: Standard baseline monitoring applies
- Firewall Rules: No specific blocking rules required
- Alerting: No elevated alerting thresholds needed
- Investigation: Not warranted absent additional contextual threats
Confidence Level: HIGH
Data Sources: 4 independent intelligence feeds
Last Updated: 2026-07-24
---
*This briefing was generated using IPDebrief threat intelligence data. All indicators are based on current observation data and should be validated against your organization's threat context.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Retelit Contact Role |
| ASN | AS3302 |
| Network Name | CLOUDITALIA |
| CIDR Block | 212.90.16.0/20 |
| RIR | RIPE |
| Country | IT |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | ip-21-58.sn-212-90.clouditalia.com |
| Forward Confirmed | Yes — FCrDNS verified |
| Forward Hostnames | ip-21-58.sn-212-90.clouditalia.com |
🔐 DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 — Basic operator with some routing infrastructure |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS3302 |
| Network Prefix | 212.90.0.0/19 |
| Route mapping | Found |
| Certificates in transparency logs | 0 certificates |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-06 18:16:49 UTC |
| Last Seen | 2026-08-27 06:50:37 UTC |
| Profile Built | 2026-08-29 05:27:36 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 23 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 212.90.21.58
Who owns the IP address 212.90.21.58?
212.90.21.58 is registered to Retelit Contact Role. The address falls within the 212.90.16.0/20 network block. Registration is held at RIPE.
Where is 212.90.21.58 located?
Geolocation data places 212.90.21.58 in Sestino, Tuscany, Italy. The local time zone is Europe/Rome. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 212.90.21.58 malicious or safe?
212.90.21.58 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 212.90.21.58?
The reverse DNS (PTR) record for 212.90.21.58 is ip-21-58.sn-212-90.clouditalia.com. This hostname is forward-confirmed, meaning it resolves back to the same address.