# IP Intelligence Briefing: 5.7.249.226/32
Classification: Low Risk | Analysis Date: July 2026
Target: 5.7.249.226 (Single Host)
## Executive Summary
IP address 5.7.249.226 presents a low-risk threat profile with no observable malicious activity. The address shows no associations with known threat campaigns, no blacklist entries, and no active services. Neighborhood analysis indicates zero abuse density in the immediate /24 subnet. No security actions required at this time.
## Threat Profile
- Risk Score: 0 (Low Risk)
- Provider Score: 0
- Authority Score: 0
- Abuse Confidence Score: Not available
- Blacklist Count: 0
## Geolocation & Ownership
- Country: United States (US-NY, New York)
- ASN: Not resolved
- Organization: Not resolved
- Geolocation Consensus: False (multiple conflicting sources detected)
- Network Classification: Firewalled / No Services
## Network Observations
- Open Ports: None detected
- DNS PTR: Not resolved
- Forward Resolution: Not configured
- Control Plane: Route stability: False, MOAS: False
- Traceroute: 30 hops, Comcast transit network identified
## Threat Indicators
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Campaign Associations: None detected
- Threat Feed Matches: None
- Certificate Matches: 0
## Historical Activity
Analysis of 10 historical observations (2026-07-29) indicates:
- DNSSEC validation checks performed
- ASN lookup returned conflicting geographic data (DE vs US)
- Port scanning detected no open services
- No significant threat signal changes observed
## Neighborhood Context
- Subnet: 5.7.249.226/24
- Abuse Density: 0.0 (None)
- Neighboring IPs: 0
- Threat Siblings: 0
- High/Medium Risk Neighbors: 0
## Relationship Graph
No related entities, hostnames, organizations, or certificates identified in the relationship network.
## Recommended Actions
No security actions recommended. The IP address demonstrates no malicious behavior patterns. Standard monitoring practices apply.
---
*Data Source: IPDebrief Threat Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Bernd Roth |
| ASN | AS6805 |
| Network Name | LEBENSHILFE-WORMS-NET |
| CIDR Block | 5.7.249.224/29 |
| RIR | RIPE |
| Country | DE |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 4% | 1 | 1 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-21 06:47:36 UTC |
| Last Seen | 2026-07-29 07:42:52 UTC |
| Profile Built | 2026-07-29 07:55:00 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 20 |
Full dossier details are available via our API.