# IP Intelligence Briefing: 82.215.106.158/32
Classification: LOW RISK / INFRASTRUCTURE
Risk Score: 25/100
Analysis Date: 2026-07-25
## Executive Summary
The IP address 82.215.106.158 exhibits low-risk characteristics with no active threat indicators. The address is associated with TurkmenTelecom infrastructure and appears to be a firewalled endpoint with no publicly accessible services. Routing stability issues and geolocation inconsistencies warrant monitoring but do not indicate malicious activity.
## Current Status
Risk Assessment:
- Overall Risk Score: 25 (Low)
- Reputation: Low Risk
- Authority Score: 0
- Provider Score: 0
- Stability Label: Not Applicable
Geolocation:
- Primary Location: Netherlands (NL), Amsterdam
- Secondary Signals: Uzbekistan (UZ), Navoiy Region
- GeoConsensus: False (multiple conflicting sources)
- GeoPlausibility: Not Validated
Network Classification:
- Origin ASN: 59668
- BGP Prefix: 82.215.96.0/20
- Routing Stability: Unstable (not consistently routed)
- Service Purpose: Firewalled / No Services
- ISP: TurkmenTelecom (turontelecom.uz)
## Threat Indicators
Malicious Activity: None Detected
- Blacklist Count: 0
- Is Known Attacker: False
- Is Tor Exit Node: False
- Is Proxy: False
- Is Spam Source: False
- Active Threat Feeds: None
- Known Campaigns: None
- DNSBL Listed: 1 of 8 lists
Technical Services:
- Open Ports: None detected
- TLS Certificates: None
- HTTP Services: None
- Reverse DNS: 82.215.106.158.ip-trans.turontelecom.uz
- Forward Resolution: Confirmed (1 hostname)
## Observation History
Total Signals: 14 observations
Risk Trajectory: Stable
Threat Persistence: 0 days
Persistence Classification: Not Persistently Malicious
Recent signal observations indicate:
- Geolocation signals from both Netherlands and Uzbekistan (conflicting data)
- Operator score: 0.1304 (Minimal)
- Low-confidence signals (0.12-0.70 confidence range)
- No escalation in threat profile over time
## Relationships
DNS Associations:
- 82.215.106.158.ip-trans.turontelecom.uz (TurkmenTelecom)
Connected Entities: 2 relationships (all DNS-based)
- No organizational links detected
- No certificate associations
- No hostname clusters beyond the primary reverse DNS entry
## Neighborhood Analysis
Subnet: 82.215.106.0/24
Abuse Density: 0%
Neighbor Classification: Low Risk
Adjacent IPs:
| IP Address | Risk Score | Classification |
|---|---|---|
| 82.215.106.68 | 25 | Low |
| 82.215.106.253 | 0 | Low |
Subnet Threat Profile: Minimal. No high or medium-risk siblings detected. Abuse density indicates this /24 subnet is not commonly abused.
## Recommended Actions
Immediate Actions: None Required
- Risk score below actionability threshold
- No active threat indicators present
- No firewall rules generated
Monitoring Recommendations:
1. Monitor for routing stability improvements (currently unstable)
2. Watch for geolocation signal convergence (NL vs UZ inconsistency)
3. Track DNSBL listing status (1 of 8 lists)
4. Monitor for service activation on previously firewalled endpoint
SOC Analyst Notes:
This IP appears to be legitimate TurkmenTelecom infrastructure with no malicious indicators. The geolocation inconsistencies and routing instability are common for international ISP ranges and do not indicate compromise. The low-risk neighborhood profile and absence of threat indicators support treating this as benign infrastructure. Standard monitoring is appropriate; no immediate blocking or alerting recommended.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | mnt-uz-turonmedia-1 |
| ASN | AS59668 |
| Network Name | UZ-TURONMEDIA-20031117 |
| CIDR Block | 82.215.96.0/20 |
| RIR | RIPE |
| Country | UZ |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | 82.215.106.158.ip-trans.turontelecom.uz |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 82.215.106.158.ip-trans.turontelecom.uz |
🔐 DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | 3/3 domains |
| DMARC | 0/3 domains |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
| Domains Checked | 3 domains |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS59668 |
| Network Prefix | 82.215.96.0/20 |
| Route mapping | Found |
| Certificates in transparency logs | 0 certificates |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 19% | 1 | 2 |
| routing | 8% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 27% | 2 | 3 |
| reputation | 8% | 1 | 1 |
| geolocation | 8% | 1 | 1 |
| Overall | 13% | 7 | 9 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-09 19:41:27 UTC |
| Last Seen | 2026-09-13 10:58:33 UTC |
| Profile Built | 2026-09-13 11:09:59 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 29 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 82.215.106.158
Who owns the IP address 82.215.106.158?
82.215.106.158 is registered to mnt-uz-turonmedia-1. The address falls within the 82.215.96.0/20 network block. Registration is held at RIPE.
Where is 82.215.106.158 located?
Geolocation data places 82.215.106.158 in Amsterdam, Navoiy Region, Netherlands. The local time zone is Europe/Amsterdam. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 82.215.106.158 malicious or safe?
82.215.106.158 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 82.215.106.158?
The reverse DNS (PTR) record for 82.215.106.158 is 82.215.106.158.ip-trans.turontelecom.uz. This hostname is not forward-confirmed, so it should be treated as a weak signal.