# IP Intelligence Briefing: 83.177.129.149/32
Classification: LOW RISK - Mobile Network Endpoint
Date: Intelligence gathered from IPDebrief platform analysis
Analyst: IPDebrief SOC Intelligence Team
---
## Executive Summary
IP address 83.177.129.149 is classified as a low-risk endpoint associated with Tele2 mobile network infrastructure. The address is currently geolocated to London, GB, but exhibits historical geographic inconsistencies with Latvia (LV). The IP operates with no active open services (firewalled/no services detected) and maintains a risk score of 25/100.
---
## Network Ownership & Infrastructure
| Attribute | Value |
|---|---|
| **ASN** | 1257 |
| **Organization** | Tele2 IP Registry |
| **Netname** | LV-TELE2-GPRS |
| **CIDR Block** | 83.177.128.0/19 |
| **RIR** | RIPE |
| **Mobile Carrier** | Tele2 Sverige AB (MCC: 240, MNC: 07) |
| **Technology** | LTE/5G |
The IP belongs to Tele2's mobile infrastructure network, operating under RIPE registry allocation. The network is classified as mobile rather than traditional infrastructure hosting.
---
## Geographic Analysis
Current Geolocation: London, GB (Europe/London timezone)
Historical Geolocation: Riga, Latvia (multiple observations)
Status: ⚠️ GEOGRAPHIC INCONSISTENCY DETECTED
The IP exhibits conflicting geographic signals across observation windows. Current profile indicates London, GB positioning, while historical observations (from July 2026) show Latvia (LV) geolocation with confidence scores ranging from 0.30 to 0.90. This inconsistency may indicate:
- Mobile device roaming/transit behavior
- CDN/anycast routing variations
- Potential proxy or relay activity (though no proxy indicators present)
---
## Threat Indicators & Reputation
| Metric | Value |
|---|---|
| **Risk Score** | 25/100 (LOW) |
| **Reputation** | Low Risk |
| **Blacklist Count** | 0 (profile) / 1 (DNSBL) |
| **Known Attacker** | No |
| **Tor Exit Node** | No |
| **Spam Source** | No |
| **Abuse Confidence** | N/A |
Threat Feeds: No known threat feeds or campaigns correlated with this address. No evidence of malicious activity patterns.
---
## Technical Services & DNS
Open Ports: None detected (firewalled/no services)
DNS PTR: m83-177-129-149.cust.tele2.lv
Forward Resolution: m83-177-129-149.cust.tele2.lv
DNSSEC Valid: Yes
CAA Records: Present
Email Auth: SPF and DMARC records present
The IP resolves to a customer-facing Tele2 hostname with proper DNSSEC validation and email authentication records configured. No web services or open ports detected.
---
## Control Plane & Route Stability
| Metric | Value |
|---|---|
| **Route Stability** | Unstable (isRouteStable: false) |
| **BGP Prefix** | 83.177.128.0/19 |
| **Origin ASN** | 1257 |
| **Route Changes (30d)** | 0 |
| **DNSBL Listings** | 1 of 8 total lists |
| **Operator Score** | 0 |
The network demonstrates route instability despite zero route changes in the past 30 days. Single DNSBL listing detected.
---
## Neighborhood Analysis
Subnet: 83.177.129.149/24
Abuse Density: 0.0
Neighbor Count: 0
Threat Siblings: 0
No sibling IPs detected in the /24 subnet. Abuse density is negligible at 0.0, indicating this is an isolated endpoint without adjacent malicious activity.
---
## Relationship Graph
| Relationship Type | Target |
|---|---|
| DNS Association | m83-177-129-149.cust.tele2.lv |
| Same Network | LV-TELE2-GPRS |
Two relationships identified: DNS hostname association and network-level connection to the LV-TELE2-GPRS network.
---
## Recommended Actions
For SOC Analysts:
1. Monitor Geographic Discrepancies: Track if the GB/LV geographic inconsistency persists. Investigate if related to legitimate mobile roaming or potential misuse.
2. Review DNSBL Status: One DNSBL listing detected. Verify if listing is active and assess source.
3. Baseline Behavior: Establish normal traffic patterns for this mobile endpoint. Given the no-services/firewalled profile, unexpected inbound connections warrant investigation.
4. Contextual Analysis: If this IP appears in security alerts, evaluate in context with associated mobile carrier Tele2 Sverige AB. Legitimate mobile traffic from this ASN may be expected.
5. No Immediate Blocking Recommended: Low risk score (25) and no known threat indicators support allowing traffic unless specific malicious activity is observed.
---
## Conclusion
IP 83.177.129.149 represents a legitimate Tele2 mobile network endpoint with low risk characteristics. The primary intelligence finding is geographic signal inconsistency between current London positioning and historical Latvia locations. No active threat indicators, malware campaigns, or abuse patterns detected. Routine monitoring recommended; no immediate defensive action required absent additional context from security events.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Tele2 IP Registry |
| ASN | AS1257 |
| Network Name | LV-TELE2-GPRS |
| CIDR Block | 83.177.128.0/19 |
| RIR | RIPE |
| Country | LV |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | m83-177-129-149.cust.tele2.lv |
| Forward Confirmed | Yes — FCrDNS verified |
| Forward Hostnames | m83-177-129-149.cust.tele2.lv |
🔐 DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | 2/2 domains |
| DMARC | 2/2 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
| Domains Checked | 2 domains |
☁️ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS1257 |
| Network Prefix | 83.176.0.0/12 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 5 |
| routing | 25% | 2 | 4 |
| services | 12% | 2 | 2 |
| ownership | 27% | 3 | 5 |
| reputation | 24% | 1 | 6 |
| geolocation | 20% | 2 | 3 |
| Overall | 23% | 12 | 25 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-12 21:07:15 UTC |
| Last Seen | 2026-09-13 19:11:23 UTC |
| Profile Built | 2026-09-13 19:13:21 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 41 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 83.177.129.149
Who owns the IP address 83.177.129.149?
83.177.129.149 is registered to Tele2 IP Registry. The address falls within the 83.177.128.0/19 network block. Registration is held at RIPE.
Where is 83.177.129.149 located?
Geolocation data places 83.177.129.149 in Riga, RIX, Sweden. The local time zone is Europe/Stockholm. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 83.177.129.149 malicious or safe?
83.177.129.149 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 83.177.129.149?
The reverse DNS (PTR) record for 83.177.129.149 is m83-177-129-149.cust.tele2.lv. This hostname is forward-confirmed, meaning it resolves back to the same address.
Is 83.177.129.149 a VPN, proxy, or data center address?
83.177.129.149 is classified as a mobile network based on network ownership and behavioural analysis.