# IPDebrief Intelligence Briefing: 216.144.249.120/32
Classification: Moderate Risk
Date: 2026-07-31
Analysis ID: 216.144.249.120-20260731
---
## Executive Summary
IP address 216.144.249.120 presents a moderate risk profile (risk score: 50) with no known malicious indicators. The address is associated with LSTN.net infrastructure and shows geolocation inconsistencies within German networks. No active threat campaigns or known attacker status has been confirmed. Recommended action: Monitor or block based on organizational policy.
---
## Technical Profile
| Attribute | Value |
|---|---|
| **IP Address** | 216.144.249.120/32 |
| **Risk Score** | 50 (Moderate Risk) |
| **ASN** | 46475 |
| **BGP Prefix** | 216.144.249.0/24 |
| **Organization** | LSTN.net (lstn.net) |
| **Location** | Germany (Bavaria, Greding) |
| **Geo Discrepancy** | Frankfurt am Main, Hesse (reported in history) |
| **Control Plane** | Route stable: false (0 route changes in 30 days) |
| **DNSBL Listings** | 2 of 8 lists |
| **Operator Score** | 0.1304 (Minimal) |
---
## Network Services
- Open Ports: None detected
- Service Classification: Firewalled / No Services
- DNS Records:
- PTR: 120-249-144-216.static.reverse.lstn.net
- Forward resolution: Confirmed (1 record)
- TLS/HTTP: No certificates, no HTTP titles detected
- Reverse DNS: Active (lstn.net domain)
---
## Threat Indicators
- Is Tor Exit: No
- Is Known Attacker: No
- Is Spam Source: No
- Blacklist Count: 0
- Pulsedive Risk: Not assessed
- Known Campaigns: None identified
- Threat Feeds: No matches
- Campaign Likelihood: None
---
## Historical Observations (13 Total)
Recent observations from 2026-07-31 show:
- Geolocation Inconsistencies: Multiple geolocation sources reported conflicting locations (Greding, Bavaria vs Frankfurt am Main, Hesse)
- Port Scanning: Detected scanning activity with nested data omitted
- Confidence Levels: Ranged from 0.12 to 0.70 across observations
- Persistence: No persistent malicious behavior detected
- Threat Observation Count: 0
---
## Relationship Graph
- DNS Associations: 120-249-144-216.static.reverse.lstn.net
- Total Relationships: 1
- Certificate Matches: 0
- Correlated IPs: 0
---
## Neighborhood Analysis (216.144.249.0/24)
- Subnet Abuse Density: 0
- Total Siblings: 0 (active)
- Risk Distribution:
- High Risk: 0
- Medium Risk: 1
- Low Risk: 2
- Notable Neighbors:
- 216.144.249.68: Risk Score 25
- 216.144.249.82: Risk Score 0
- 216.144.249.201: Risk Score 60
---
## Recommended Security Actions
Firewall Rules
```bash
# iptables
iptables -A INPUT -s 216.144.249.120 -j DROP
# nftables
nft add rule inet filter input ip saddr 216.144.249.120 drop
# Nginx
deny 216.144.249.120;
# pfSense
216.144.249.120/32
# Cloudflare WAF
{"description":"Block 216.144.249.120 โ IPDebrief risk score 50","action":"block","filter":{"expression":"ip.src eq 216.144.249.120"}}
# AWS WAF
{"Addresses":["216.144.249.120/32"],"Description":"IPDebrief risk 50"}
```
---
## Risk Assessment
Threat Level: MODERATE
Key Findings:
1. No direct malicious activity confirmed
2. DNSBL listings indicate some reputation concerns
3. Geolocation inconsistencies warrant monitoring
4. Route stability flag set to false (route changes observed)
5. No evidence of hosting, VPN, proxy, or CDN services
Mitigation:
- Implement blocking rules per firewall platform recommendations
- Monitor for emerging threat indicators
- Track geolocation consistency over time
Recommendation: Block traffic from this IP address based on current risk profile. Reassess after 30 days if no new threat indicators emerge.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Limestone Networks, Inc. |
| ASN | AS46475 |
| Network Name | LIMESTONE-NETWORKS |
| CIDR Block | 216.144.240.0/20 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 120-249-144-216.static.reverse.lstn.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 120-249-144-216.static.reverse.lstn.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-30 11:03:50 UTC |
| Last Seen | 2026-08-01 04:25:39 UTC |
| Profile Built | 2026-07-31 02:25:59 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 22 |
Full dossier details are available via our API.