# IP INTELLIGENCE BRIEFING
Target: 79.204.17.101/32
Date: 2026-06-23
Classification: Low Risk / Residential Mobile Connection
---
## EXECUTIVE SUMMARY
IP 79.204.17.101 is a low-risk mobile network address assigned to Deutsche Telekom AG (ASN 3320) in Bensberg, Germany. The IP presents minimal threat indicators with a risk score of 25/100. No active services, open ports, or known malicious activity detected. Classification indicates a residential mobile connection with firewalled/no services observed.
---
## NETWORK OWNERSHIP & GEOLOCATION
| Attribute | Value |
|---|---|
| **ASN** | 3320 (DTAG-NIC) |
| **Organization** | Deutsche Telekom AG |
| **Country** | Germany (DE) |
| **Region** | North Rhine-Westphalia |
| **City** | Bensberg |
| **RIR** | RIPE |
| **Mobile Carrier** | Telekom (Deutsche Telekom AG) |
| **Connection Type** | Mobile (LTE/5G) |
Geolocation Confidence: High โ Multiple validation sources confirm plausible location with 168.6km distance from claimed coordinates.
---
## THREAT ASSESSMENT
Overall Risk Score: 25/100 (Low Risk)
Threat Indicators:
- Blacklist Count: 0
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- DNSBL Listings: 1 of 8 checked lists
- Abuse Confidence Score: Not applicable
Network Classification:
- Provider Infrastructure: No
- CDN/Hosting/VPN/Proxy: No
- Mobile Network: Yes
- Residential: No
- Bogon: No
---
## NETWORK ROLE & SERVICES
Service Status: Firewalled / No Services Detected
- Open Ports: None
- TLS Certificates: None
- HTTP Banner: None
Control Plane Analysis:
- Route Stability: False
- DNSSEC Valid: Yes
- Operator Score: 0.2609 (Basic)
- Route Changes (30d): 0
---
## DNS ANALYSIS
| Metric | Value |
|---|---|
| PTR Hostname | p4fcc1165.dip0.t-ipconnect.de |
| Forward Resolution | Confirmed (1 record) |
| Domain | t-ipconnect.de |
| SPF Record | No |
| DMARC Record | No |
| TXT Records | 0 |
---
## OBSERVATION HISTORY
Total Observations: 22 signals
Recent Activity Summary:
- June 23, 2026: Reputation signal observed (confidence: 0.30)
- June 18, 2026: Multiple signals including geolocation (avg RTT: 112ms), subnet classification ("mostly_clean"), and operator scoring
Risk Trend: No significant escalation observed. IP maintains low-risk profile with minimal threat persistence.
---
## RELATIONSHIP GRAPH
Total Relationships: 25
- Same Network Associations: 25 instances to DTAG-DIAL24 network
- DNS Associations: 6 instances to p4fcc1165.dip0.t-ipconnect.de
Network Context: IP belongs to the DTAG-DIAL24 network block, consistent with Deutsche Telekom residential/mobile infrastructure.
---
## NEIGHBORHOOD ANALYSIS
Subnet: 79.204.17.101/24
- Abuse Density: 0 (Low)
- Classification: Mostly Clean
- Inherited Risk: 2/100
- Active Siblings: 0
- Threat Siblings: 1
---
## RECOMMENDED ACTIONS
Security Actions: None Required
- Risk score below threshold for blocking
- No active malicious indicators
- Standard monitoring recommended
Firewall Rules: None generated
Note: Low-risk mobile residential connections should be permitted with standard rate limiting and monitoring. No immediate remediation required.
---
## INTELLIGENCE CONCLUSION
IP 79.204.17.101 represents a legitimate Deutsche Telekom mobile network endpoint with no evidence of malicious activity. The low risk score, absence of threat indicators, and classification as a residential mobile connection support continued network access. SOC teams should maintain standard logging and monitoring procedures without additional restrictions.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | DTAG-NIC |
| ASN | AS3320 |
| Network Name | โ |
| CIDR Block | 79.192.0.0/10 |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | p4fcc1165.dip0.t-ipconnect.de |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | p4fcc1165.dip0.t-ipconnect.de |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 21% | 9 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:35 UTC |
| Last Seen | 2026-06-23 21:43:01 UTC |
| Profile Built | 2026-06-23 21:55:25 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 27 |
Full dossier details are available via our API.