# IP INTELLIGENCE BRIEFING: 27.79.1.91/32
## Executive Summary
IP 27.79.1.91 presents a low-risk profile with no active threat indicators. The address belongs to BGP prefix 27.79.0.0/21 (ASN 7552) with minimal operator impact. No active services, open ports, or malicious behavior observed. No security actions recommended at this time.
---
## Profile Overview
| Attribute | Value |
|---|---|
| **Risk Score** | 0 (Low Risk) |
| **Reputation** | Low Risk |
| **Provider Score** | 0 |
| **Authority Score** | 0 |
| **Stability Score** | 0 |
| **Classification** | Firewalled / No Services |
| **Open Ports** | None |
---
## Geolocation & Network Attribution
- Primary Location: US, Illinois, Chicago
- BGP Prefix: 27.79.0.0/21
- Origin ASN: 7552 (Viettel Group, VN)
- RIR Registry: APNIC (allocated 2010-04-27)
- Country Code Discrepancy: RIR records indicate Vietnam (VN), while geolocation data shows US
- Route Stability: Unstable (isRouteStable: false)
- Route Changes (30d): 0
---
## Threat Indicators
- Blacklist Count: 0
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Threat Feeds: None populated
- Pulsedive Risk: Not applicable
- Campaign Matches: 0
---
## DNS Analysis
- PTR Hostname: localhost
- Forward Resolution: localhost (not confirmed)
- Reverse DNS Confirmed: No
- Hosted Domains: None
- Email Auth (SPF/DMARC): Not configured
- DNSSEC: Valid
- Forward Resolution Count: 1
---
## Services & Behavioral Analysis
- HTTP/HTTPS: No services detected
- TLS Certificate: None
- Banner/Title: None captured
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: 0
- Auto-Banned: No
- Active Attacker Status: No
---
## Observation History (17 total signals)
Recent activity observed through 2026-07-29:
- Operator Score: 0.1304 (Minimal)
- DNSSEC Validation: Confirmed
- ASN Attribution: Consistent (7552)
- Signal Confidence: Variable (0.16-0.90)
- Threat Persistence: 0 days
- Ownership Changes: 0
No escalation in threat posture over observed period.
---
## Network Neighborhood (27.79.1.0/24)
| Metric | Value |
|---|---|
| **Total Sibling IPs** | 17 |
| **Abuse Density** | 0 |
| **High Risk Neighbors** | 0 |
| **Medium Risk Neighbors** | 10 |
| **Low Risk Neighbors** | 7 |
Notable Sibling Risk Scores:
- 27.79.1.152: 65
- 27.79.1.172: 55
- 27.79.1.14/15/26/69/70/84/85/87/107/116/226/245: 15-40 range
---
## Traceroute Analysis
- Hop Count: 21
- First Hop RTT: 0.1ms
- Last Hop RTT: 245.9ms
- Timed Out Hops: 6
- Transit Networks: Comcast, Cogent
---
## Recommended Security Actions
No actionable firewall rules or blocking recommendations at this time. The IP presents minimal risk with no active threat indicators, no open services, and no evidence of malicious behavior.
Monitoring Recommendations:
- Continue passive observation of subnet 27.79.1.0/24
- Monitor for service activation on target IP
- Watch for changes in reverse DNS or email authentication records
---
## Intelligence Assessment
IP 27.79.1.91 is classified as a firewalled address with no active services. The low-risk score (0) combined with zero blacklist listings and absence of threat indicators indicates benign operation. Geographic discrepancies between RIR records (Vietnam) and geolocation data (US) warrant periodic verification but do not indicate malicious activity. The subnet exhibits mixed risk profiles with 10 medium-risk siblings, suggesting potential shared infrastructure usage but no direct correlation to the target IP.
Confidence Level: High
Recommended Action: Monitor / No Action Required
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-VNNIC-AP |
| ASN | AS7552 |
| Network Name | VIETTEL-VN |
| CIDR Block | 27.64.0.0/12 |
| RIR | APNIC |
| Country | VN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | localhost |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | localhost |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 26% | 2 | 2 |
| Overall | 23% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-22 13:24:21 UTC |
| Last Seen | 2026-08-13 06:46:12 UTC |
| Profile Built | 2026-08-13 10:15:00 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 47 |
Full dossier details are available via our API.