# IP Intelligence Briefing
Target: 2607:fb90:6881:2225:2024:107:72d1:c396/128
Date: September 11, 2026
Classification: Low Risk - Residential Mobile Endpoint
---
## Executive Summary
The target IPv6 address belongs to T-Mobile USA, Inc. (AS21928) and is classified as a low-risk mobile carrier endpoint. No malicious indicators, threat activity, or abuse patterns have been observed. The IP is firewalled with no active services detected.
---
## Ownership & Network Context
| Attribute | Value |
|---|---|
| **Organization** | T-Mobile USA, Inc. |
| **ASN** | AS21928 |
| **Network** | TMOV6-1 (2607:fb90:6800::/40) |
| **RIR** | ARIN |
| **Registration** | 2009-07-14 |
| **Abuse Contact** | abuse@t-mobile.com |
---
## Geolocation
Multiple geolocation sources indicate the endpoint is located in Massachusetts, USA:
- MaxMind GeoLite2: Boston, MA (42.3388, -71.0726)
- AlienVault OTX: Lawrence, MA (42.6915, -71.1579)
- Team Cymru Country: US (39.83, -98.58) - country-level only
All sources confirm US territory with geolocation consensus achieved. ICMP validation was blocked during geolocation probing.
---
## Risk Assessment
Risk Score: 0/100 (Low Risk)
Reputation: Low Risk
Abuse Confidence: N/A
Threat Indicators: None
Blacklist Count: 0
Threat Indicators Verified:
- Not a Tor exit node
- Not a known attacker IP
- Not a spam source
- No threat feed matches
- No known campaigns associated
Behavioral Analysis:
- No honeypot hits
- No enumeration strikes
- No WAF violations
- No active attacker behavior detected
---
## Network Activity & Services
Service Scan Results: Ports 80, 443, 22, 8080, 8443, 25, and 3389 were scanned. No open services detected.
Network Role Classification:
- Mobile Carrier: Yes (T-Mobile LTE/5G)
- CDN: No
- Cloud: No
- Proxy: No
- VPN: No
- Hosting: No
- Bogon: No
DNS Analysis:
- PTR record: None
- Forward resolution: Failed
- DNSSEC: Invalid
- Domain: Not resolved
---
## Neighborhood Analysis
Subnet: 2607:fb90:6881:2225:2024:107:72d1:c396/48
Abuse Density: 0 (Clean)
Active Siblings: 0
Threat Siblings: 0
The /48 subnet contains no other active endpoints. This appears to be a single residential mobile endpoint with zero abuse density inherited from the neighborhood.
---
## Historical Observations
Total Signals: 19 observations collected
Data Freshness: Live (most recent: 2026-09-11T15:41:07 UTC)
Temporal Analysis:
- No ownership changes detected
- No threat persistence observed
- No evolving risk patterns
- Stable network classification
---
## Related Entities
Nine relationships identified, all pointing to the same network "TMOV6-1". No external associations to hostnames, organizations, or certificates detected.
---
## Recommended Actions
Firewall Policy: Allow (info)
Threat Response: No action required
The target IP represents a benign residential mobile endpoint from a major carrier. No blocking or investigation is warranted. Standard monitoring practices apply.
---
*Intelligence generated from IPDebrief analysis platform. Data sufficiency: Very Low (0.2667 confidence due to limited service probing on residential mobile endpoint).*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | T-Mobile USA, Inc. |
| ASN | AS21928 |
| Network Name | TMOV6-1 |
| CIDR Block | β |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 0% (None) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 35% | 2 | 2 |
| ownership | 25% | 1 | 2 |
| reputation | 25% | 1 | 1 |
| geolocation | 25% | 1 | 1 |
| Overall | 26% | 7 | 8 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-09-11 15:34:09 UTC |
| Last Seen | 2026-09-11 15:34:09 UTC |
| Profile Built | 2026-09-11 15:46:58 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 20 |
Full dossier details are available via our API.