# IP Intelligence Briefing: 78.111.249.76/32
Date: July 29, 2026
Analyst: IPDebrief Intelligence Team
Classification: Network Threat Intelligence
---
## Executive Summary
IP address 78.111.249.76 is classified as High Risk (Risk Score: 80/100) with a residential mobile connection profile. The endpoint is associated with Rostelecom's TVINGO network infrastructure in Vladikavkaz, North Ossetia-Alania, Russia. Despite the elevated risk classification, the IP shows no active threat indicators, open services, or known malicious activity at time of analysis.
---
## Technical Profile
| Attribute | Value |
|---|---|
| **IP Address** | 78.111.249.76/32 |
| **Risk Score** | 80 (High Risk) |
| **ASN** | 12389 |
| **Organization** | PJSC Rostelecom Technical Team |
| **Network** | TVINGO (78.111.248.0/21) |
| **Country** | Russia (RU) |
| **City/Region** | Vladikavkaz, North Ossetia-Alania |
| **Infrastructure Type** | Residential |
| **Connection Type** | Mobile (LTE) |
| **Mobile Carrier** | Tele2 RU |
| **RIR** | RIPE |
---
## Network Classification
- Provider/Infrastructure: Residential endpoint
- Cloud/CDN/Proxy: No
- Tor/VPN: Not detected
- Hosting: No
- Bogon: No
- Anycast: No
DNS Resolution: `pppoe-78-111-249-76.dynamic.tvingo.ru`
Forward Resolution: Confirmed
PTR Record: pppoe-78-111-249-76.dynamic.tvingo.ru
---
## Threat Indicators
| Indicator | Status |
|---|---|
| **Abuse Confidence Score** | Not Available |
| **Blacklist Count** | 0 |
| **Known Campaigns** | None |
| **Threat Feeds** | Empty |
| **Open Ports** | None Detected |
| **TLS Certificate** | None |
| **HTTP Services** | None |
| **Is Known Attacker** | False |
| **Is Spam Source** | False |
| **Is Tor Exit Node** | False |
Control Plane:
- BGP Prefix: 78.111.248.0/22
- Route Stability: Unstable
- DNSBL Listed: 5 of 8 total lists
- RPKI State: Not Available
---
## Neighborhood Analysis (78.111.249.0/24)
- Abuse Density: Clean (0%)
- Active Siblings: 0
- Threat Siblings: 0
- Total Siblings: 1
*Note: No neighboring IPs detected in the /24 subnet.*
---
## Observation History
Recent signal observations from July 29, 2026 indicate:
- Multiple port scanning activities recorded
- Geographic validation challenges (ICMP blocked, unable to validate)
- Geo location plausible (claimed coordinates: 43.0357° N, 44.6721° E)
- No ownership changes detected
- No persistent malicious behavior observed
---
## Relationships
| Type | Target |
|---|---|
| DNS Association | pppoe-78-111-249-76.dynamic.tvingo.ru |
| Same Network | TVINGO |
*Seven relationship entries identified, primarily DNS and network associations.*
---
## Recommended Actions
Current Recommendations: None
Given the residential mobile connection profile and lack of active threat indicators, immediate blocking is not warranted. However, the elevated risk score (80) suggests monitoring is recommended.
Suggested Monitoring Actions:
1. Traffic Logging: Log all traffic from this IP for 30-day observation period
2. Reputation Monitoring: Watch for changes in blacklist status or threat feed listings
3. Behavioral Analysis: Monitor for any emergence of open ports or service activity
4. Subnet Awareness: Consider monitoring related IPs in 78.111.248.0/21 block
---
## Intelligence Assessment
This IP represents a residential mobile endpoint within Rostelecom's TVINGO infrastructure. The high risk classification appears to be derived from network classification factors rather than confirmed malicious activity. The clean neighborhood profile and absence of threat indicators suggest this may be a false positive classification or a residential IP that has been flagged based on historical patterns.
Confidence Level: Moderate
Recommended Priority: Low (Monitor)
Immediate Action Required: No
---
*Intel prepared by IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | PJSC Rostelecom Technical Team |
| ASN | AS12389 |
| Network Name | TVINGO |
| CIDR Block | 78.111.248.0/21 |
| RIR | RIPE |
| Country | RU |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | pppoe-78-111-249-76.dynamic.tvingo.ru |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | pppoe-78-111-249-76.dynamic.tvingo.ru |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Residential |
| Service Purpose | Residential Endpoint |
| Network Tier | End-User β Residential ISP endpoint |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 25% | 1 | 1 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-23 13:57:26 UTC |
| Last Seen | 2026-07-29 19:07:53 UTC |
| Profile Built | 2026-07-29 19:24:29 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 22 |
Full dossier details are available via our API.