# IP Intelligence Briefing: 84.1.34.96
Date: 2026-07-31
Classification: Moderate Risk โ Residential/Static DSL
Risk Score: 50/100
---
## Executive Summary
IP address 84.1.34.96 is a static residential DSL endpoint located in Budapest, Hungary, operated by Telekom Hungary (ASN 5483). The address presents a moderate risk profile with multi-service host characteristics. While the IP itself shows no active malicious indicators, it is situated in a subnet with one high-risk neighbor (84.1.34.242, risk score 80). The IP is currently listed on 2 of 8 known DNS blocklists and exhibits basic operational characteristics consistent with residential broadband.
---
## Network Ownership & Classification
- Organization: MTELEKOM-MNT (Telekom Hungary)
- Network Name: MT-BROADBAND-STATIC-DSL
- CIDR Block: 84.1.34.0/23
- ASN: 5483
- RIR: RIPE
- Classification: Multi-Service Host
- Connection Type: Static Residential DSL
---
## Geolocation Data
- Country: Hungary (HU)
- City: Budapest
- Coordinates: 47.16°N, 19.5°E
- Timezone: Europe/Budapest
- GeoValidation: Plausible (confirmed via 5 probes, 200km accuracy radius)
- RTT Analysis: Min 146ms, Avg 153.6ms, Max 159ms
---
## DNS & Service Analysis
- PTR Hostname: dsl54012260.fixip.t-online.hu
- Forward Resolution: Confirmed to t-online.hu domain
- Email Authentication: SPF and DMARC records present
- Open Ports:
- Port 80/TCP (HTTP)
- Port 22/TCP (SSH) โ Banner: SSH-2.0-ROSSSH
No TLS certificates detected; HTTP title and banner data unavailable.
---
## Threat Intelligence Profile
- Reputation Sources: None active
- Abuse Confidence Score: Not calculated
- Known Campaigns: None
- Blacklist Count: 0 direct entries
- DNSBL Listings: 2 of 8 lists
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
---
## Control Plane Analysis
- BGP Origin Prefix: 84.0.0.0/14
- Route Stability: Unstable
- RPKI State: Not verified
- DNSSEC Valid: Yes
- Operator Score: 0.2609 (Basic classification)
---
## Neighborhood Assessment
- Subnet: 84.1.34.0/24
- Total Siblings: 2
- Active Siblings: 1
- Abuse Density: Low (1)
- Threat Siblings: 0
Notable Neighbor: 84.1.34.242 โ Risk Score 80 (HIGH), Authority Score 70. This neighbor warrants separate investigation and monitoring.
---
## Historical Signal Analysis
Observation history shows 21 recorded signals from 2026-07-31 with stable characteristics:
- No ownership changes detected
- Zero threat observation count
- No persistent malicious behavior identified
- Geolocation and network role signals consistent across observations
---
## Recommended Actions
Firewall Rules (Block Recommendation)
iptables:
```
iptables -A INPUT -s 84.1.34.96 -j DROP
```
nftables:
```
nft add rule inet filter input ip saddr 84.1.34.96 drop
```
nginx:
```
deny 84.1.34.96;
```
pfSense:
```
84.1.34.96/32
```
Cloudflare WAF:
```json
{"description":"Block 84.1.34.96 โ IPDebrief risk score 50","action":"block","filter":{"expression":"ip.src eq 84.1.34.96"}}
```
AWS WAF:
```json
{"Addresses":["84.1.34.96/32"],"Description":"IPDebrief risk 50"}
```
---
## Intelligence Narrative
IP 84.1.34.96 is a static residential endpoint associated with Telekom Hungary's broadband infrastructure. The moderate risk score of 50 reflects its residential DSL classification and the presence of open SSH and HTTP services. The IP's DNS configuration is properly authenticated with SPF and DMARC records. While the address itself shows no active malicious indicators, its subnet neighbor (84.1.34.242) presents elevated risk.
The 2 DNSBL listings suggest historical association with potentially suspicious activity, though no current threat indicators are present. Route instability and basic operator scoring indicate this is not a critical infrastructure endpoint but rather a consumer-facing static IP.
Recommendation: Implement blocking at the perimeter layer with monitoring on the neighboring IP 84.1.34.242. The residential nature of this endpoint means false positive blocking may impact legitimate users, so consider time-based blocking or rate limiting rather than permanent drops if business continuity requirements exist.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | MTELEKOM-MNT |
| ASN | AS5483 |
| Network Name | MT-BROADBAND-STATIC-DSL |
| CIDR Block | 84.1.34.0/23 |
| RIR | RIPE |
| Country | HU |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | dsl54012260.fixip.t-online.hu |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | dsl54012260.fixip.t-online.hu |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Multi-Service Host |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 443, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-ROSSSH |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-29 22:50:53 UTC |
| Last Seen | 2026-08-13 06:45:22 UTC |
| Profile Built | 2026-08-10 17:30:11 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 24 |
Full dossier details are available via our API.