## IP Intelligence Briefing: 78.112.51.207
Classification: Moderate Risk (Score: 40/100)
Report Date: 2026-06-23
Analysis Type: Full Profile Assessment
---
Executive Summary
IP 78.112.51.207 is a mobile carrier-assigned address operated by SFR (Societe Francaise du Radiotelephone) from Lyon, France. The IP exhibits moderate risk characteristics with a risk score of 40 and is associated with 2 DNSBL listings. No active threat indicators (Tor exit, spam source, or known attacker) were detected. The address operates on LTE/5G mobile technology with no open services detected.
---
Technical Profile
Ownership & Registration:
- ASN: 15557 (SFR Legal Contact)
- Organization: Societe Francaise du Radiotelephone (SFR)
- Network: N9UF-DYN-DSL (Dynamic DSL Network)
- RIR: RIPE
Geolocation:
- Country: France (FR)
- City: Lyon
- Region: Rhône-Alpes
- Timezone: Europe/Paris
- Location Accuracy: 500km radius
Network Classification:
- Type: Mobile Device (SFR carrier)
- Connection Technology: LTE/5G (MCC: 208, MNC: 10)
- Services: No open ports detected (Firewalled/No Services)
- Proxy/VPN/CDN: None detected
DNS Analysis:
- PTR Record: 207.51.112.78.rev.sfr.net
- Forward Resolution: Confirmed
- Forward Hostnames: 207.51.112.78.rev.sfr.net
- Email Auth: SPF enabled, DMARC not configured
---
Threat Assessment
Risk Indicators:
- Risk Score: 40 (Moderate)
- Blacklist Count: 0 (direct blacklists)
- DNSBL Listed: 2 of 8 total lists
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
Control Plane:
- Route Stability: False
- Operator Score: 0.2609 (Basic classification)
- RPKI State: Not assessed
- DNSSEC: Valid
- Route Changes (30d): 0
Neighborhood Analysis:
- Subnet: 78.112.51.207/24
- Abuse Density: 0.5 (Moderate)
- Classification: Mostly Clean
- Total Siblings: 2
- Threat Siblings: 1
- Notable Neighbor: 78.112.51.86 (Risk Score: 25)
---
Historical Observations
Signal Timeline:
- Total Observations: 18
- Most Recent: 2026-06-23T21:34:48Z
- Threat Observation Count: 1
- Threat Persistence Days: 0
- Persistently Malicious: No
Temporal Trends:
- Ownership Changes: 0
- Recent subnet abuse density signal (2026-06-18): 0.5 (mostly_clean)
---
Relationship Network
Associated Entities:
- DNS Associations: 207.51.112.78.rev.sfr.net (multiple records)
- Network Associations: N9UF-DYN-DSL (24 instances)
- Total Relationships: 31
Relationship Types:
- Same Network: Primary classification
- DNS Association: Reverse DNS mappings
---
Recommended Actions
Firewall Recommendations:
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 78.112.51.207 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 78.112.51.207 drop` |
| nginx | `deny 78.112.51.207;` |
| pfSense | `78.112.51.207/32` |
| Cloudflare WAF | Block IP (Risk Score: 40) |
| AWS WAF | Address: 78.112.51.207/32 |
Analysis Notes:
- No open services detected; firewall rules are precautionary
- Mobile carrier IP with moderate risk score
- Consider context of observed traffic before implementing blocking
- DNSBL listing on 2 of 8 lists warrants investigation
- Monitor for changes in threat indicators or neighborhood activity
---
End of Briefing
*This intelligence briefing is based on IPDebrief threat intelligence data. Recommendations should be validated with additional signals before operational implementation.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | SFR Legal Contact |
| ASN | AS15557 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 207.51.112.78.rev.sfr.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | 207.51.112.78.rev.sfr.net |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 26% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 21% | 9 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:34 UTC |
| Last Seen | 2026-06-23 21:33:57 UTC |
| Profile Built | 2026-06-23 21:41:56 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 20 |
Full dossier details are available via our API.