IP Intelligence Briefing: 79.254.114.249
*Last Updated: 2026-06-11*
---
**Key Risk Profile**
- Risk Score: 50 (Moderate Risk)
- Provider: Deutsche Telekom AG (AS3320)
- Geolocation:
- Reported Country: United States (NY)
- Mobile Carrier: Deutsche Telekom (Germany, LTE/5G)
- Discrepancy: Geolocation conflicts with mobile carrier data (Germany vs. US). Verify with additional probes.
---
**Network & Ownership**
- ASN: 3320 (DTAG-NIC)
- Network: DTAG-DIAL27 (79.252.0.0/14)
- Subnet: 79.254.114.249/24 (0 active/abusive neighbors detected)
- Hosting: Mobile device (no cloud/CDN/residential indicators)
---
**Threat Indicators**
- No Malicious Activity: No DNS, TLS, or service-based threats detected.
- Blacklist Status: Not listed in major DNSBLs.
- Historical Trends: No persistent malicious behavior (0 threat observations in 30 days).
---
**Relationships & Context**
- DNS Associations: Linked to `p4ffe72f9.dip0.t-ipconnect.de` (Telekom domain).
- Network Peers: Subnet shares same provider (DTAG-NIC) but no abusive siblings.
- Email/Reputation: No SPF/DMArc records; no email-based threats.
---
**Actionable Insights**
1. Geolocation Discrepancy: Investigate why the IP reports US location despite being tied to a German mobile carrier. Possible spoofing or misconfigured DNS.
2. Monitor for Changes: Track risk score shifts or unexpected service activations (e.g., TLS/HTTP).
3. Network Segmentation: Isolate mobile traffic if this IP belongs to a critical system.
No immediate mitigation required, but continuous monitoring is advised due to conflicting metadata.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | DTAG-NIC |
| ASN | AS3320 |
| Network Name | DTAG-DIAL27 |
| CIDR Block | 79.252.0.0/14 |
| RIR | RIPE |
| Country | DE |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | p4ffe72f9.dip0.t-ipconnect.de |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | p4ffe72f9.dip0.t-ipconnect.de |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 13% | 1 | 1 |
| routing | 13% | 1 | 1 |
| services | 13% | 1 | 1 |
| ownership | 30% | 2 | 3 |
| reputation | 0% | 0 | 0 |
| geolocation | 13% | 1 | 1 |
| Overall | 14% | 6 | 7 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-26 06:51:41 UTC |
| Last Seen | 2026-06-11 04:18:06 UTC |
| Profile Built | 2026-06-11 04:52:22 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 22 |
Full dossier details are available via our API.