# INTELLIGENCE BRIEFING: 79.106.123.238/32
Date: 2026-07-24
Classification: LOW RISK
Risk Score: 25/100
---
## EXECUTIVE SUMMARY
IP address 79.106.123.238 presents a low-risk profile with no active threat indicators. The asset is associated with ALBTELECOM-MNT (AS42313) and belongs to the 79.106.96.0/19 block. No services are actively running; the host is classified as firewalled with no open ports. Neighborhood analysis indicates a clean subnet with zero abuse density.
---
## NETWORK ATTRIBUTES
| Attribute | Value |
|---|---|
| **ASN** | 42313 |
| **Organization** | ALBTELECOM-MNT |
| **Netname** | TEST3028 |
| **CIDR Block** | 79.106.96.0/19 |
| **RIR** | RIPE |
| **Geolocation** | GB (London) / AL (Tirana) - *inconsistent data sources* |
| **Timezone** | Europe/London |
---
## THREAT ASSESSMENT
Current Risk Score: 25/100 (Low Risk)
Abuse Confidence Score: Not applicable
Blacklist Status: 1 DNSBL listing of 8 total (high severity)
Known Campaigns: None
Tor Exit Node: No
Known Attacker: No
Spam Source: No
Threat Indicators: Empty
Threat Feeds: No matches
Persistence Status: Not persistently malicious
---
## SERVICE AND PORT ANALYSIS
Open Ports: None detected
TLS Certificate: Not found
HTTP Title: Not found
Server Banner: Not found
Service Classification: Firewalled / No Services
DNS Forward Resolution: 0 records
PTR Hostnames: None
---
## SUBNET NEIGHBORHOOD ANALYSIS (79.106.123.0/24)
| Metric | Value |
|---|---|
| **Total Siblings** | 3 |
| **Active Siblings** | 0 |
| **Threat Siblings** | 0 |
| **Abuse Density** | 0 |
| **Classification** | Clean |
Neighbor IPs:
- 79.106.123.55 (Risk: 0, Authority: 50)
- 79.106.123.138 (Risk: 0, Authority: 50)
The /24 subnet demonstrates no correlated threat activity.
---
## RELATIONSHIP GRAPH
Limited relationship connectivity detected:
- Same Network: TEST3028 (2 entries)
- No associated hostnames, organizations, or certificates beyond network-level attribution
---
## OBSERVATION HISTORY
Total Observations: 14 signals recorded
Recent Activity:
- 2026-07-24 15:22:19 UTC: Ownership signal (confidence: 85%)
- 2026-07-24 15:19:48 UTC: Organization attribution to ALBTELECOM-MNT (confidence: 90%)
- 2026-07-24 15:18:57 UTC: DNSBL listing detected (confidence: 85%, 1 of 8 lists, high severity)
Temporal Indicators:
- Ownership Changes: 0
- Threat Observation Count: 0
- Threat Persistence Days: 0
---
## RECOMMENDED ACTIONS
No specific firewall rules or blocking recommendations generated. Current risk profile does not warrant immediate mitigation measures.
---
## SOC ANALYST NOTES
Key Observations:
1. The IP maintains a stable low-risk profile with no evidence of malicious activity
2. Geographic data shows inconsistency between GB (London) and AL (Tirana) sources—monitor for resolution
3. Single DNSBL listing warrants periodic review but does not indicate active abuse
4. No open services reduce attack surface
5. Clean neighborhood environment suggests this is not part of a malicious cluster
Monitoring Recommendations:
- Track DNSBL listing status periodically
- Monitor for service activation if previously dormant
- Verify geographic attribution consistency
Disposition: LOW PRIORITY — No immediate action required. Maintain standard monitoring protocols.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | ALBTELECOM-MNT |
| ASN | AS42313 |
| Network Name | TEST3028 |
| CIDR Block | 79.106.96.0/19 |
| RIR | RIPE |
| Country | AL |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Residential |
| Service Purpose | Residential Endpoint |
| Network Tier | End-User — Residential ISP endpoint |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS42313 |
| Network Prefix | 79.106.123.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 25% | 1 | 1 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-07 18:44:02 UTC |
| Last Seen | 2026-08-27 05:42:32 UTC |
| Profile Built | 2026-08-29 05:41:56 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 19 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 79.106.123.238
Who owns the IP address 79.106.123.238?
79.106.123.238 is registered to ALBTELECOM-MNT. The address falls within the 79.106.96.0/19 network block. Registration is held at RIPE.
Where is 79.106.123.238 located?
Geolocation data places 79.106.123.238 in London, Tirana, United Kingdom. The local time zone is Europe/London. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 79.106.123.238 malicious or safe?
79.106.123.238 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
Is 79.106.123.238 a VPN, proxy, or data center address?
79.106.123.238 is classified as a residential network based on network ownership and behavioural analysis.