IPDebrief

83.177.129.149

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 83.177.129.149/32

Classification: LOW RISK - Mobile Network Endpoint

Date: Intelligence gathered from IPDebrief platform analysis

Analyst: IPDebrief SOC Intelligence Team

---

## Executive Summary

IP address 83.177.129.149 is classified as a low-risk endpoint associated with Tele2 mobile network infrastructure. The address is currently geolocated to London, GB, but exhibits historical geographic inconsistencies with Latvia (LV). The IP operates with no active open services (firewalled/no services detected) and maintains a risk score of 25/100.

---

## Network Ownership & Infrastructure

AttributeValue
**ASN**1257
**Organization**Tele2 IP Registry
**Netname**LV-TELE2-GPRS
**CIDR Block**83.177.128.0/19
**RIR**RIPE
**Mobile Carrier**Tele2 Sverige AB (MCC: 240, MNC: 07)
**Technology**LTE/5G

The IP belongs to Tele2's mobile infrastructure network, operating under RIPE registry allocation. The network is classified as mobile rather than traditional infrastructure hosting.

---

## Geographic Analysis

Current Geolocation: London, GB (Europe/London timezone)

Historical Geolocation: Riga, Latvia (multiple observations)

Status: ⚠️ GEOGRAPHIC INCONSISTENCY DETECTED

The IP exhibits conflicting geographic signals across observation windows. Current profile indicates London, GB positioning, while historical observations (from July 2026) show Latvia (LV) geolocation with confidence scores ranging from 0.30 to 0.90. This inconsistency may indicate:

---

## Threat Indicators & Reputation

MetricValue
**Risk Score**25/100 (LOW)
**Reputation**Low Risk
**Blacklist Count**0 (profile) / 1 (DNSBL)
**Known Attacker**No
**Tor Exit Node**No
**Spam Source**No
**Abuse Confidence**N/A

Threat Feeds: No known threat feeds or campaigns correlated with this address. No evidence of malicious activity patterns.

---

## Technical Services & DNS

Open Ports: None detected (firewalled/no services)

DNS PTR: m83-177-129-149.cust.tele2.lv

Forward Resolution: m83-177-129-149.cust.tele2.lv

DNSSEC Valid: Yes

CAA Records: Present

Email Auth: SPF and DMARC records present

The IP resolves to a customer-facing Tele2 hostname with proper DNSSEC validation and email authentication records configured. No web services or open ports detected.

---

## Control Plane & Route Stability

MetricValue
**Route Stability**Unstable (isRouteStable: false)
**BGP Prefix**83.177.128.0/19
**Origin ASN**1257
**Route Changes (30d)**0
**DNSBL Listings**1 of 8 total lists
**Operator Score**0

The network demonstrates route instability despite zero route changes in the past 30 days. Single DNSBL listing detected.

---

## Neighborhood Analysis

Subnet: 83.177.129.149/24

Abuse Density: 0.0

Neighbor Count: 0

Threat Siblings: 0

No sibling IPs detected in the /24 subnet. Abuse density is negligible at 0.0, indicating this is an isolated endpoint without adjacent malicious activity.

---

## Relationship Graph

Relationship TypeTarget
DNS Associationm83-177-129-149.cust.tele2.lv
Same NetworkLV-TELE2-GPRS

Two relationships identified: DNS hostname association and network-level connection to the LV-TELE2-GPRS network.

---

## Recommended Actions

For SOC Analysts:

1. Monitor Geographic Discrepancies: Track if the GB/LV geographic inconsistency persists. Investigate if related to legitimate mobile roaming or potential misuse.

2. Review DNSBL Status: One DNSBL listing detected. Verify if listing is active and assess source.

3. Baseline Behavior: Establish normal traffic patterns for this mobile endpoint. Given the no-services/firewalled profile, unexpected inbound connections warrant investigation.

4. Contextual Analysis: If this IP appears in security alerts, evaluate in context with associated mobile carrier Tele2 Sverige AB. Legitimate mobile traffic from this ASN may be expected.

5. No Immediate Blocking Recommended: Low risk score (25) and no known threat indicators support allowing traffic unless specific malicious activity is observed.

---

## Conclusion

IP 83.177.129.149 represents a legitimate Tele2 mobile network endpoint with low risk characteristics. The primary intelligence finding is geographic signal inconsistency between current London positioning and historical Latvia locations. No active threat indicators, malware campaigns, or abuse patterns detected. Routine monitoring recommended; no immediate defensive action required absent additional context from security events.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇸🇪 Sweden
RegionRIX
CityRiga
TimezoneEurope/Stockholm
Latitude56.95
Longitude24.10

🏢 Ownership & Registration

OrganizationTele2 IP Registry
ASNAS1257
Network NameLV-TELE2-GPRS
CIDR Block83.177.128.0/19
RIRRIPE
CountryLV
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRm83-177-129-149.cust.tele2.lv
Forward ConfirmedYes — FCrDNS verified
Forward Hostnamesm83-177-129-149.cust.tele2.lv

🔐 DNS Hygiene

Hygiene Score100% (Excellent)
SPF2/2 domains
DMARC2/2 domains
FCrDNSVerified
DNSSECValid
CAAPresent
Domains Checked2 domains

☁️ Network Classification

InfrastructureMobile
Service PurposeFirewalled / No Services
Network TierUnknown — Insufficient routing data to classify
Mobile

🔌 Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Server—
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS1257
Network Prefix83.176.0.0/12
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
33%
25
routing
25%
24
services
12%
22
ownership
27%
35
reputation
24%
16
geolocation
20%
23
Overall23%1225
Coverage: 6/6 dimensions · Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) — 1 contradiction(s)
AttributionModerate (55%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Geo sources disagree on country: LV, SE

📅 Observation Timeline 🔄 Live

First Seen2026-07-12 21:07:15 UTC
Last Seen2026-09-13 19:11:23 UTC
Profile Built2026-09-13 19:13:21 UTC
Data FreshnessLive
Signal Types26
Total Observations41
🔍 26 signal types · 41 observations collected
This report is generated from 26+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 83.177.129.149

Who owns the IP address 83.177.129.149?

83.177.129.149 is registered to Tele2 IP Registry. The address falls within the 83.177.128.0/19 network block. Registration is held at RIPE.

Where is 83.177.129.149 located?

Geolocation data places 83.177.129.149 in Riga, RIX, Sweden. The local time zone is Europe/Stockholm. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 83.177.129.149 malicious or safe?

83.177.129.149 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.

What is the hostname for 83.177.129.149?

The reverse DNS (PTR) record for 83.177.129.149 is m83-177-129-149.cust.tele2.lv. This hostname is forward-confirmed, meaning it resolves back to the same address.

Is 83.177.129.149 a VPN, proxy, or data center address?

83.177.129.149 is classified as a mobile network based on network ownership and behavioural analysis.

🏘️ Related IP Addresses

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.