IPDebrief

74.248.96.101

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING: 74.248.96.101/32

Classification: Moderate Risk

Date: 2024-01-15

Analysis Scope: Full profile, historical observation, network relationships, and neighborhood assessment

---

## EXECUTIVE SUMMARY

IP address 74.248.96.101 operates within Microsoft Azure cloud infrastructure with a moderate risk score of 65/100. The IP shows no persistent malicious behavior, no active threat indicators, and resides in a clean subnet. However, the elevated risk score warrants increased monitoring or blocking depending on organizational threat tolerance.

---

## TECHNICAL PROFILE

AttributeValue
**IP Address**74.248.96.101/32
**Risk Score**65/100 (Moderate Risk)
**ASN**8075 (Microsoft Azure)
**Organization**BTR ADSL CBB
**Netname**BLS-74-248-64-0-1003020949
**CIDR Block**74.248.64.0/18
**Registry**ARIN
**Geolocation**Poland (Warsaw, Mazovia)
**Infrastructure**Cloud Compute (Azure)
**Service Status**Firewalled / No Services

---

## THREAT INDICATORS

Assessment: No active threat indicators present. The IP does not appear in known attacker databases or threat feeds.

---

## NETWORK CONTEXT

Neighborhood Analysis (74.248.96.0/24)

Related IPs

IP AddressRisk ScoreClassification
74.248.96.4725/100Low
74.248.96.10525/100Low

Neighborhood Risk: Minimal. The subnet shows low abuse activity with only two low-risk sibling IPs.

---

## OBSERVATION HISTORY

Total Observations: 16 signals tracked

Recent Activity (2026-07-30)

Trend Assessment: Stable ownership with no persistent malicious behavior detected. No escalating threat patterns observed.

---

## NETWORK ROLE & SERVICES

Operational Note: The IP presents as firewalled with no publicly accessible services.

---

## CONTROL PLANE DATA

MetricValue
**BGP Prefix**74.248.0.0/15
**Route Stability**Not stable
**MOAS**No
**RPKI State**N/A
**Route Changes (30d)**0
**DNSSEC Valid**Yes
**Operator Score**0.1304 (Minimal)

---

## RECOMMENDED ACTIONS

Monitoring

Firewall Rules (Blocking Recommended)

PlatformRule
iptables`iptables -A INPUT -s 74.248.96.101 -j DROP`
nftables`nft add rule inet filter input ip saddr 74.248.96.101 drop`
nginx`deny 74.248.96.101;`
pfSense`74.248.96.101/32`
Cloudflare WAFBlock IP with description "IPDebrief risk score 65"
AWS WAFAdd IP to blacklist with description "IPDebrief risk 65"

---

## SOC ANALYST DECISION FRAMEWORK

FactorAssessment
**Risk Score**65/100 (Moderate)
**Threat Indicators**None detected
**Subnet Reputation**Clean
**Infrastructure**Legitimate Azure cloud
**Recommendation****Monitor or Block** based on organizational risk tolerance

Actionable Guidance

1. If risk tolerance is low: Block the IP using provided firewall rules

2. If risk tolerance is moderate: Monitor traffic patterns and review logs

3. Investigate further if: Associated with successful attack attempts, unusual traffic patterns, or policy violations

---

Report Generated By: IPDebrief Intelligence Platform

Data Source: IPDebrief Real-Time Intelligence Database

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ต๐Ÿ‡ฑ Poland
RegionMZ
CityWarsaw
TimezoneEurope/Warsaw
Latitude52.23
Longitude21.01

๐Ÿข Ownership & Registration

OrganizationBTR ADSL CBB
ASNAS8075
Network NameBLS-74-248-64-0-1003020949
CIDR Block74.248.64.0/18
RIRARIN
CountryUnited States
Abuse Contactโ€”

๐ŸŒ DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)

๐Ÿ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
35%
23
routing
13%
11
services
19%
22
ownership
19%
22
reputation
15%
12
geolocation
25%
11
Overall21%911
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) โ€” 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Geo sources disagree on country: US, PL

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-07-25 21:01:18 UTC
Last Seen2026-08-12 20:01:36 UTC
Profile Built2026-08-12 20:11:07 UTC
Data FreshnessLive
Signal Types20
Total Observations22
๐Ÿ” 20 signal types ยท 22 observations collected
This report is generated from 20+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.