IPDebrief

213.230.93.108

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 213.230.93.108

## Executive Summary

IP address 213.230.93.108 is registered to UZTELECOM (AS8193) and located in Tashkent, Uzbekistan. The address carries a risk score of 80 (High Risk) and is listed on 7 DNS blacklists. While the IP itself shows no active threat indicators, the surrounding subnet demonstrates elevated abuse activity requiring defensive attention.

---

## Network Profile

## Technical Characteristics

## Threat Indicators

## Geographic Intelligence

Multiple geo-location observations confirm Uzbekistan origin with coordinates centered on Tashkent region (41.26°N, 69.22°E). Recent signals indicate varying geo-location data points including Nukus region, suggesting possible spoofing or inconsistent reporting sources.

## Subnet Neighborhood Analysis

The /24 subnet (213.230.93.0/24) shows moderate abuse concentration:

## Relationship Graph

---

## Recommended Actions

Immediate Mitigation

1. Block at Network Perimeter: Implement egress/ingress firewall rules to deny traffic from 213.230.93.0/24 subnet

2. DNS Sinkholing: Consider sinkhole for 108.64.uzpak.uz hostname if resolution attempts occur

3. IDS/IPS Rules: Deploy signatures for traffic patterns matching this subnet's profile

Monitoring Recommendations

1. Subnet Surveillance: Monitor all 15 sibling IPs in 213.230.93.0/24 for coordinated activity

2. DNS Monitoring: Track DNS queries to uzpak.uz domain for potential C2 or infrastructure use

3. Threat Intelligence Feeds: Add to watchlist due to 7/8 DNSBL listings and risk score of 80

Escalation Criteria

---

## Intelligence Assessment

This IP represents a defensive priority due to its high risk score and extensive blacklist presence, though no active threat indicators are currently observable. The subnet's abuse density warrants ongoing monitoring. The lack of open services suggests this may be part of bulk hosting infrastructure potentially repurposed for abuse. Recommend maintaining blocklist entries and monitoring for emergence of active scanning or connection attempts.

Classification: Defensive Priority - Monitor

Last Updated: 2026-07-31

Confidence Level: High

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Ώ UZ
RegionTashkent
CityTashkent
Timezoneβ€”
Latitude41.26
Longitude69.22

🏒 Ownership & Registration

OrganizationAS8193-MNT
ASNAS8193
Network NameUZTELECOM
CIDR Block213.230.93.0/24
RIRRIPE
CountryUZ
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR108.64.uzpak.uz
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnames108.64.uzpak.uz

πŸ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown β€” Insufficient routing data to classify
No specific classification

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
35%
22
routing
25%
11
services
25%
11
ownership
0%
00
reputation
25%
11
geolocation
0%
00
Overall18%55
Coverage: 4/6 dimensions Β· Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-07-30 11:03:50 UTC
Last Seen2026-08-01 04:25:39 UTC
Profile Built2026-07-31 02:23:54 UTC
Data FreshnessLive
Signal Types22
Total Observations22
πŸ” 22 signal types Β· 22 observations collected
This report is generated from 22+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.