# IP Intelligence Briefing: 79.186.223.251/32
## Executive Summary
IP 79.186.223.251 is classified as Low Risk with an overall risk score of 15. The address is assigned to Orange-Swiatlowod (ASN 5617) under TP S.A. Hostmaster. Current threat indicators are minimal, with no active malicious campaigns detected. The IP is identified as a mobile carrier connection from Orange Polska S.A., operating within the 79.186.0.0/16 block.
## Ownership and Network Classification
- Organization: TP S.A. Hostmaster
- Netname: Orange-Swiatlowod
- ASN: 5617
- RIR: Ripe
- CIDR Block: 79.186.0.0/16
- Network Type: Mobile Carrier (LTE/5G)
- Carrier: Orange Polska S.A. (MCC: 260, MNC: 03)
- Service Status: Firewalled / No Services (no open ports detected)
## Geolocation Analysis
Geolocation data shows conflicting signals:
- Primary Classification: United States (US-NY)
- Secondary Classification: Poland (PL)
- GeoConsensus: False (indicates conflicting geolocation sources)
- GeoPlausible: False
- Forward Resolution: Confirmed via PTR record to 79.186.223.251.ipv4.supernova.orange.pl
## Threat Intelligence
- Risk Score: 15 (Low)
- Provider Score: 0
- Authority Score: 0
- Abuse Confidence Score: Not available
- Blacklist Status: Listed on 1 of 8 DNSBL lists (medium severity)
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Active Campaigns: None detected
- Threat Persistence Days: 0
## Historical Observations
17 total observations recorded. Most recent activity detected on 2026-07-27. Signal types include:
- Network classification signals
- Organization and ASN resolution
- DNS and domain association
- Blacklist monitoring (1 listing observed)
## Relationship Graph
Two primary relationships identified:
1. DNS Association: 79.186.223.251.ipv4.supernova.orange.pl
2. Same Network: Orange-Swiatlowod
## Neighborhood Analysis
- Subnet: 79.186.223.251/24
- Abuse Density: 0 (clean classification)
- Total Siblings: 1
- Active Siblings: 0
- Threat Siblings: 0
## Recommended Actions
No specific firewall or mitigation rules generated due to low risk classification. However, the single DNSBL listing warrants periodic monitoring.
## Intelligence Assessment
This IP address represents a legitimate mobile carrier connection with minimal threat activity. The conflicting geolocation data (US vs. PL) is consistent with mobile roaming patterns. No evidence of abuse, malicious activity, or campaign association detected. The IP is properly registered with TP S.A. Hostmaster and operates within normal mobile network parameters. SOC analysts may monitor the single blacklist listing but no immediate blocking action is required.
---
*Intel generated by IPDebrief for defensive security purposes.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | TP S.A. Hostmaster |
| ASN | AS5617 |
| Network Name | Orange-Swiatlowod |
| CIDR Block | 79.186.0.0/16 |
| RIR | RIPE |
| Country | PL |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | 79.186.223.251.ipv4.supernova.orange.pl |
| Forward Confirmed | Yes — FCrDNS verified |
| Forward Hostnames | 79.186.223.251.ipv4.supernova.orange.pl |
🔐 DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | 2/2 domains |
| DMARC | 2/2 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
| Domains Checked | 2 domains |
☁️ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS5617 |
| Network Prefix | 79.184.0.0/13 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 23% | 2 | 4 |
| routing | 17% | 2 | 3 |
| services | 12% | 2 | 2 |
| ownership | 19% | 3 | 4 |
| reputation | 20% | 1 | 3 |
| geolocation | 17% | 2 | 3 |
| Overall | 18% | 12 | 19 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-12 08:52:14 UTC |
| Last Seen | 2026-09-02 18:35:59 UTC |
| Profile Built | 2026-09-02 18:38:09 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 33 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 79.186.223.251
Who owns the IP address 79.186.223.251?
79.186.223.251 is registered to TP S.A. Hostmaster. The address falls within the 79.186.0.0/16 network block. Registration is held at RIPE.
Where is 79.186.223.251 located?
Geolocation data places 79.186.223.251 in Poznan, Greater Poland, Poland. The local time zone is Europe/Warsaw. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 79.186.223.251 malicious or safe?
79.186.223.251 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 79.186.223.251?
The reverse DNS (PTR) record for 79.186.223.251 is 79.186.223.251.ipv4.supernova.orange.pl. This hostname is forward-confirmed, meaning it resolves back to the same address.
Is 79.186.223.251 a VPN, proxy, or data center address?
79.186.223.251 is classified as a mobile network based on network ownership and behavioural analysis.