# IP Intelligence Briefing: 217.97.204.34/32
## Executive Summary
This IP address presents a Moderate Risk profile (55/100) with evidence of mobile network activity and multi-service hosting. While no confirmed threat indicators exist, the risk score warrants monitoring and consideration for defensive filtering.
---
## Network Ownership & Registration
- ASN: 5617 (M-CONNECT)
- Organization: Krzysztof Baran
- CIDR Block: 217.97.204.0/25
- RIR: RIPE
- Abuse Contact: Available via RDAP
---
## Geolocation & Network Classification
- Country: Poland (PL)
- Region: Lubusz
- City: Jasieล
- Coordinates: 51.92°N, 19.15°E
- Timezone: Europe/Warsaw
Classification Flags:
- Mobile Network: Yes (Orange Polska S.A., LTE/5G, MCC: 260, MNC: 03)
- Cloud/CDN/VPN/Proxy: No
- Residential: No
- Hosting: No
- Tor Exit Node: No
---
## Service Fingerprint
- Port 80 (TCP): HTTP (lighttpd/1.4.39)
- Port 22 (TCP): SSH (dropbear, curve25519-sha256 enabled)
- DNS: Forward resolution failed
- Email Auth: No SPF/DMARC records detected
- TLS Certificate: None observed
---
## Threat Intelligence Indicators
- Blacklist Count: 0
- DNSBL Listings: 3 of 8 total lists
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
---
## Neighborhood Analysis (217.97.204.0/24)
- Subnet Abuse Density: 0 (Clean)
- Total Sibling IPs: 5
- Active Siblings: 3
- Threat Siblings: 0
- Risk Distribution: 3 medium-risk, 0 high-risk, 0 low-risk
- Notable Neighbors: 217.97.204.54, 217.97.204.62, 217.97.204.85 (all Risk 55)
---
## Observation History
- Total Observations: 15 signals
- Recent Activity: 2026-07-30
- Risk Persistence: Not persistently malicious
- Observation Types: Port scans, service banners, geolocation inference, operator scoring
---
## Control Plane Status
- BGP Prefix: 217.97.0.0/16
- Route Stability: Unstable
- RPKI State: Not validated
- DNSSEC: Valid
- Operator Score: 0.1304 (Minimal)
---
## Recommended Security Actions
Immediate Recommendations
1. Increase logging verbosity and review recent activity from this IP (Risk Score: 55/100)
Firewall Rules
| System | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 217.97.204.34 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 217.97.204.34 drop` |
| nginx | `deny 217.97.204.34;` |
| pfSense | `217.97.204.34/32` |
| Cloudflare WAF | Block with expression: `ip.src eq 217.97.204.34` |
| AWS WAF | Address: `217.97.204.34/32`, Description: `IPDebrief risk 55` |
---
## Assessment Notes
This IP operates on a mobile network (Orange Polska) with standard web and SSH services. The moderate risk score stems from operator scoring and minimal threat signals rather than confirmed malicious activity. No correlated IPs or campaign associations detected. The subnet shows a pattern of 3 medium-risk siblings, suggesting potential coordinated activity. Monitoring is recommended, especially given the mobile network classification and multi-service hosting role.
---
*Report generated: IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Krzysztof Baran |
| ASN | AS5617 |
| Network Name | M-CONNECT |
| CIDR Block | 217.97.204.0/25 |
| RIR | RIPE |
| Country | PL |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Multi-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 443, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | lighttpd/1.4.39 |
| HTTP Title | โ |
| SSH Version | SSH-2.0-dropbear <?-?A>l}?v??????curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-grou |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 50% | 2 | 3 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 20% | 5 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-26 03:09:00 UTC |
| Last Seen | 2026-08-07 13:24:46 UTC |
| Profile Built | 2026-08-05 18:37:17 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.