IPDebrief

78.31.234.52

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 78.31.234.52/32

Date: 2026-07-27

Classification: Low Risk

Risk Score: 25/100

---

## Executive Summary

IP address 78.31.234.52 presents a low-risk profile with a risk score of 25. The IP is registered to RIPE NCC under ASN 60014 (LIR-IR-ABRAMAD-1-MNT) with network block 78.31.232.0/22. No active services were detected, and the IP exhibits minimal threat indicators. However, inconsistent geolocation data and one DNS blacklist listing warrant monitoring.

---

## Ownership & Registration

---

## Geolocation Analysis

Assessment: Geolocation data is inconsistent. Multiple sources indicate US, but one signal shows Iran. This discrepancy requires further investigation.

---

## Threat Indicators

Assessment: No active threat indicators present. Single DNSBL listing suggests potential but unconfirmed reputation issues.

---

## Network Services & Behavior

Assessment: IP appears passive with no open services or active listening ports.

---

## DNS Analysis

Assessment: DNS configuration includes SPF and DMARC records. Forward resolution not confirmed, suggesting potential reverse DNS misconfiguration or use of a static PTR record.

---

## Neighborhood Analysis (78.31.234.0/24)

Assessment: Subnet exhibits no abuse activity. IP stands alone without correlated risk indicators from neighboring addresses.

---

## Relationship Graph

Assessment: Relationships are limited to network and DNS associations with no additional hostnames, organizations, or certificates detected.

---

## Temporal Analysis

Assessment: IP demonstrates stability in ownership with no persistent malicious behavior detected over time.

---

## Control Plane Data

Assessment: DNSSEC validation present. One DNSBL listing suggests potential reputation filtering but not definitive malicious activity.

---

## Recommended Actions

No specific firewall rules or security actions were generated by the system. Given the low-risk profile, no immediate blocking or allowlisting is required.

---

## SOC Analyst Notes

1. Monitor Geolocation Discrepancy: One observation shows Iran while profile indicates US. Investigate source of conflicting data.

2. Verify DNSBL Listing: Single DNS blacklist listing warrants verification. Check specific list for context and legitimacy.

3. Confirm Forward Resolution: PTR record exists but forward resolution not confirmed. May indicate static configuration.

4. Subnet Monitoring: Neighbor subnet 78.31.234.0/24 shows zero abuse density. No lateral threat indicators present.

5. No Immediate Action Required: Current risk score of 25 supports continued monitoring without intervention.

Priority: Low

Recommendation: Continue passive monitoring; no blocking required.

---

*Report generated using IPDebrief intelligence platform data.*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇺🇸 United States
RegionUS-MA
CityBoston
TimezoneAmerica/New_York
Latitude42.36
Longitude-71.06

🏢 Ownership & Registration

Organizationlir-ir-abramad-1-MNT
ASNAS60014
Network NameIR-ABRAMAD-20180619
CIDR Block78.31.232.0/22
RIRRIPE
CountryIR
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR78.31.234.52.abramad.com
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnames78.31.234.52.abramad.com

🔐 DNS Hygiene

Hygiene Score60% (Good)
SPFPresent
DMARCPresent
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown — Insufficient routing data to classify
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Server—
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS60014
Network Prefix78.31.234.0/23
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
35%
22
routing
25%
11
services
25%
11
ownership
25%
12
reputation
25%
11
geolocation
0%
00
Overall22%67
Coverage: 5/6 dimensions · Data sufficiency: partial
Data CoherenceMostly Consistent (80%) — 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Geo sources disagree on country: IR, US

📅 Observation Timeline 🔄 Live

First Seen2026-07-15 04:06:34 UTC
Last Seen2026-07-27 20:35:38 UTC
Profile Built2026-08-30 20:07:42 UTC
Data FreshnessLive
Signal Types21
Total Observations23
🔍 21 signal types · 23 observations collected
This report is generated from 21+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 78.31.234.52

Who owns the IP address 78.31.234.52?

78.31.234.52 is registered to lir-ir-abramad-1-MNT. The address falls within the 78.31.232.0/22 network block. Registration is held at RIPE.

Where is 78.31.234.52 located?

Geolocation data places 78.31.234.52 in Boston, US-MA, United States. The local time zone is America/New_York. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 78.31.234.52 malicious or safe?

78.31.234.52 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.

What is the hostname for 78.31.234.52?

The reverse DNS (PTR) record for 78.31.234.52 is 78.31.234.52.abramad.com. This hostname is not forward-confirmed, so it should be treated as a weak signal.

🏘️ Related IP Addresses

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.