IPDebrief

83.2.189.45

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# INTELLIGENCE BRIEFING: 83.2.189.45/32

Classification: Moderate Risk

Date: Current Analysis

Analyst: IPDebrief Intelligence Operations

---

## EXECUTIVE SUMMARY

IP address 83.2.189.45 presents a moderate risk profile (score: 55/100) associated with a mobile endpoint in Poland. The IP is classified as a mobile device on the Orange Polska network and shows no active campaign indicators. Despite listing on three DNS blacklists, threat indicators remain absent. The subnet exhibits zero abuse density, suggesting isolated rather than coordinated malicious activity.

---

## OWNERSHIP & GEOLOCATION

AttributeValue
**IP Address**83.2.189.45/32
**ASN**5617
**Organization**Krzysztof Baran
**Network Name**M-CONNECT
**Country**Poland (PL)
**City**Grodzisk Mazowiecki
**Region**Mazovia
**RIR**RIPE
**CIDR Block**83.2.189.0/24
**Mobile Carrier**Orange Polska S.A. (Orange)
**Connection Type**LTE/5G Mobile

The IP is registered to Krzysztof Baran under the M-CONNECT network. Geographic validation confirms plausibility with 5 probe measurements and an average round-trip time of 131.6ms from analysis origin.

---

## NETWORK CHARACTERISTICS

The endpoint operates a minimal web and SSH stack typical of a mobile host rather than infrastructure hosting.

---

## THREAT INDICATORS

IndicatorStatus
**Known Attacker**Negative
**Tor Exit Node**Negative
**Spam Source**Negative
**Active Campaigns**None
**Certificate Matches**0
**Banner Matches**0
**Correlated IPs**0
**Blacklist Count**0
**DNSBL Listings**3 of 8 total lists

No active threat indicators detected. The IP does not appear in known attacker databases or active campaign correlative data.

---

## NEIGHBORHOOD ANALYSIS

The /24 subnet shows zero abuse density with no active siblings, indicating this IP operates in isolation without associated malicious neighbors.

---

## OBSERVATION HISTORY

Historical signals reveal consistent ownership and geolocation attributes with no evidence of ownership changes or persistent malicious behavior. The IP has maintained stable characteristics throughout observation periods.

---

## CONTROL PLANE DATA

---

## RECOMMENDED ACTIONS

Immediate Recommendations (Risk Score: 55/100)

Category: Monitoring

Firewall Rules

PlatformRule
**iptables**`iptables -A INPUT -s 83.2.189.45 -j DROP`
**nftables**`nft add rule inet filter input ip saddr 83.2.189.45 drop`
**nginx**`deny 83.2.189.45;`
**pfSense**`83.2.189.45/32`
**Cloudflare WAF**Block IP with expression `ip.src eq 83.2.189.45`
**AWS WAF**Add IP 83.2.189.45/32 to block list

---

## INTELLIGENCE ASSESSMENT

This IP represents a moderate-risk mobile endpoint in Poland with no active threat indicators. The presence on three DNS blacklists without corresponding threat indicators suggests the listing may be outdated or based on historical activity. The mobile classification and clean subnet neighborhood support a non-infrastructure operational profile.

Priority: Monitor

Action: Apply blocking rules if business requires; consider allowing with enhanced logging if legitimate use is expected.

---

*This briefing is based on IPDebrief intelligence data. Recommendations are probabilistic and should be combined with other signals before taking action.*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ต๐Ÿ‡ฑ Poland
RegionMazovia
CityGrodzisk Mazowiecki
TimezoneEurope/Warsaw
Latitude51.92
Longitude19.15

๐Ÿข Ownership & Registration

OrganizationKrzysztof Baran
ASNAS5617
Network NameM-CONNECT
CIDR Block83.2.189.0/24
RIRRIPE
CountryPL
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)

๐Ÿ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureMobile
Service PurposeMulti-Service Host
Network TierUnknown โ€” Insufficient routing data to classify
Mobile

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
22sshtcp
Closed Ports25, 443, 3389, 8080, 8443 (2 open / 7 scanned)
Serverlighttpd/1.4.39
HTTP Titleโ€”
SSH VersionSSH-2.0-dropbear F?D?????????8hcurve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group1

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
0%
00
reputation
0%
00
geolocation
50%
23
Overall20%56
Coverage: 4/6 dimensions ยท Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-07-27 03:36:32 UTC
Last Seen2026-07-30 10:49:51 UTC
Profile Built2026-07-30 11:02:19 UTC
Data FreshnessLive
Signal Types18
Total Observations19
๐Ÿ” 18 signal types ยท 19 observations collected
This report is generated from 18+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.