Intelligence Briefing: IP 217.5.115.98
The IP address 217.5.115.98 was identified as a mobile endpoint located in Frankfurt am Main, Germany. Ownership records attributed the address to Deutsche Telekom AG (ASN 3320, DTAG-DIAL13) under the RIPE registry. Geolocation validation confirmed the location in Hesse with high consensus accuracy.
Network analysis indicated the host operated on mobile infrastructure (Telekom, LTE/5G) and was firewalled with no open ports, services, or TLS certificates. The overall reputation was Low Risk with a score of 25. Control Plane data noted 1 DNSBL listing among 8 total lists. While threat indicators were present, the system classified the host as a "Suspicious Host" without specific campaign attribution.
Neighborhood assessment classified the /24 subnet as clean with an abuse density of 0 and no active threat siblings. Behavioral logs showed no honeypot hits, enumeration strikes, or incidents. DNS hygiene was rated fair, with DMARC configured but SPF absent. Data freshness confirmed activity from September 6, 2026, through September 24, 2026.
The recommended action was to monitor traffic at low severity due to the clean neighborhood classification. No specific firewall rules were required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | DTAG-NIC |
| ASN | AS3320 |
| Network Name | DTAG-DIAL13 |
| CIDR Block | 217.0.0.0/14 |
| RIR | RIPE |
| Country | DE |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | f-ed11-i.F.DE.NET.DTAG.DE |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | f-ed11-i.F.DE.NET.DTAG.DE |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | 0/2 domains |
| DMARC | 2/2 domains |
| FCrDNS | Verified |
| DNSSEC | Not signed |
| CAA | Not configured |
| Domains Checked | 2 domains |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 43% | 2 | 5 |
| Overall | 24% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-09-06 16:38:15 UTC |
| Last Seen | 2026-09-24 05:54:43 UTC |
| Profile Built | 2026-09-24 06:10:50 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 30 |
Full dossier details are available via our API.