# IP Intelligence Briefing: 79.126.193.48
## Executive Summary
IP address 79.126.193.48 is a residential endpoint with moderate risk scoring (40/100). The IP is associated with residential broadband provider infrastructure and is currently listed on 2 of 8 threat feeds with high severity ratings. No active threat indicators or campaign correlations observed.
## Profile Overview
- IP Address: 79.126.193.48/32
- Risk Score: 40 (Moderate Risk)
- ASN: 16333 (A1MK-AS16333)
- Organization: MNT-CableTEL / MK-ONEVIP-INTERNET
- Geolocation: Vienna, Austria (AT) / RIR: RIPE
- CIDR Block: 79.126.192.0/18
- Network Classification: Residential Endpoint
## Threat Indicators
- DNSBL Listings: 2 of 8 total lists
- Blacklist Count: 0
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Open Ports: None detected
- Threat Persistence: Not persistently malicious
## Network Context & Relationships
- Infrastructure Type: Residential broadband
- Connection Type: Residential endpoint
- Related Network: MK-ONEVIP-INTERNET
- BGP Prefix: 79.126.128.0/17
- Route Stability: Not stable (route changes observed)
- Neighbor Analysis: Subnet 79.126.193.48/24 shows 0 abuse density with no sibling IPs flagged
## Historical Observations (12 total signals)
Recent activity (2026-07-22) indicates:
- Listed on 8 total threat lists with 2 high-severity entries
- DNSSEC validation: Valid
- PTR Records: None (no reverse DNS resolution)
- ASN Registration: Macedonia (MK), allocated 2007-09-13
- Infrastructure classification consistently marked as residential
## Behavioral Indicators
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: 0
- Total Incidents: 0
- Auto-IP: Status not available
## Risk Assessment
The IP presents moderate risk primarily due to DNSBL listings. The residential classification suggests legitimate end-user traffic rather than infrastructure abuse. No evidence of active exploitation, scanning, or campaign participation. The ASN geolocation discrepancy (Austria geolocation vs. Macedonia registration) warrants monitoring but does not indicate immediate threat.
## Recommendations for SOC Analysts
1. Monitor DNSBL listing status for changes
2. Allow legitimate residential traffic (no immediate block required)
3. Correlate any future activity with the 2 high-severity blacklist entries
4. Track route stability changes for potential infrastructure shifts
Confidence Level: Moderate – Residential endpoint with historical blacklist presence but no active threat indicators.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | MNT-CableTEL |
| ASN | AS16333 |
| Network Name | MK-ONEVIP-INTERNET |
| CIDR Block | 79.126.192.0/18 |
| RIR | RIPE |
| Country | MK |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Residential |
| Service Purpose | Residential Endpoint |
| Network Tier | End-User — Residential ISP endpoint |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS16333 |
| Network Prefix | 79.126.128.0/17 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 3 |
| routing | 8% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 17% | 2 | 3 |
| reputation | 8% | 1 | 1 |
| geolocation | 12% | 2 | 2 |
| Overall | 13% | 8 | 11 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-02 04:22:15 UTC |
| Last Seen | 2026-09-14 06:00:41 UTC |
| Profile Built | 2026-09-14 06:11:28 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 24 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 79.126.193.48
Who owns the IP address 79.126.193.48?
79.126.193.48 is registered to MNT-CableTEL. The address falls within the 79.126.192.0/18 network block. Registration is held at RIPE.
Where is 79.126.193.48 located?
Geolocation data places 79.126.193.48 in Vienna, Negotino, Austria. The local time zone is Europe/Vienna. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 79.126.193.48 malicious or safe?
79.126.193.48 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
Is 79.126.193.48 a VPN, proxy, or data center address?
79.126.193.48 is classified as a residential network based on network ownership and behavioural analysis.