IP Intelligence Briefing: 217.211.208.125
Date: 2026-06-08
---
**1. IP Profile**
- Risk Score: 80 (High Risk)
- Ownership:
- ASN: 3301 (TELIANET-LIR)
- Organization: Telia Company AB (Sweden)
- Geolocation:
- Country: United States (Newark, NJ)
- Mobile Carrier: Telia (Sweden)
- Network Role: Mobile Carrier (LTE/5G)
- Threat Indicators:
- No malicious activity detected (no indicators, blacklists, or campaigns).
- DNS: PTR record resolves to `217-211-208-125-no2550.tbcn.telia.com` (Telia domain).
- Services: No open ports or TLS certificates detected.
---
**2. Observation History**
- Recent Activity (Last 30 Days):
- BGP Prefix: 217.208.0.0/13 (Telia Sweden)
- Geolocation: Confirmed as Sweden (Gävleborg County) via MaxMind, but geolocation validation marked as not plausible (possible routing anomalies).
- Traceroute: Successfully reached the target with 21 hops.
- DNSSEC: Validated as secure.
- Abuse Confidence: No abuse reports detected.
---
**3. Relationships**
- DNS Associations:
- Linked to `217-211-208-125-no2550.tbcn.telia.com` (Telia subdomain).
- Network Affiliation:
- Part of TELIANET (Telia Sweden) network.
- No Known Campaigns or Threat Feeds:
- No correlation with malicious clusters or known attacker IPs.
---
**4. Neighborhood Analysis**
- Subnet: 217.211.208.125/24
- Neighbor Data:
- No active neighbors detected in the subnet.
- Abuse Density: 0% (low risk of subnet-wide malicious activity).
---
**5. SOC Recommendations**
- Monitor for Anomalies:
- Investigate the geolocation inconsistency (US vs. Sweden). This could indicate routing anomalies or misconfigured mobile carrier IP ranges.
- Verify DNSSEC and BGP Validity:
- Confirm Teliaβs BGP prefix and DNSSEC validation to ensure no spoofing or hijacking.
- Check for Unusual Traffic Patterns:
- Since the IP is mobile carrier-grade, monitor for unexpected data volumes or connections to high-risk domains.
- No Immediate Blocking Required:
- No malicious indicators detected. However, the high risk score suggests further investigation into network configuration or potential misattribution.
---
Conclusion: This IP is registered to Telia Sweden but geolocated in the US, with no direct malicious activity detected. The high risk score may stem from network configuration or routing anomalies. SOC teams should validate geolocation data and monitor for unexpected traffic patterns.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | TELIANET-LIR |
| ASN | AS3301 |
| Network Name | TELIANET |
| CIDR Block | 217.211.0.0/16 |
| RIR | RIPE |
| Country | SE |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 217-211-208-125-no2550.tbcn.telia.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 217-211-208-125-no2550.tbcn.telia.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 13% | 1 | 1 |
| routing | 13% | 1 | 1 |
| services | 13% | 1 | 1 |
| ownership | 30% | 2 | 3 |
| reputation | 0% | 0 | 0 |
| geolocation | 17% | 1 | 1 |
| Overall | 14% | 6 | 7 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Fresh
| First Seen | 2026-05-18 15:26:27 UTC |
| Last Seen | 2026-06-26 18:11:08 UTC |
| Profile Built | 2026-06-16 02:17:00 UTC |
| Data Freshness | Fresh |
| Signal Types | 19 |
| Total Observations | 19 |
Full dossier details are available via our API.