IPDebrief

84.1.34.96

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 84.1.34.96

Date: 2026-07-31

Classification: Moderate Risk โ€“ Residential/Static DSL

Risk Score: 50/100

---

## Executive Summary

IP address 84.1.34.96 is a static residential DSL endpoint located in Budapest, Hungary, operated by Telekom Hungary (ASN 5483). The address presents a moderate risk profile with multi-service host characteristics. While the IP itself shows no active malicious indicators, it is situated in a subnet with one high-risk neighbor (84.1.34.242, risk score 80). The IP is currently listed on 2 of 8 known DNS blocklists and exhibits basic operational characteristics consistent with residential broadband.

---

## Network Ownership & Classification

---

## Geolocation Data

---

## DNS & Service Analysis

- Port 80/TCP (HTTP)

- Port 22/TCP (SSH) โ€“ Banner: SSH-2.0-ROSSSH

No TLS certificates detected; HTTP title and banner data unavailable.

---

## Threat Intelligence Profile

---

## Control Plane Analysis

---

## Neighborhood Assessment

Notable Neighbor: 84.1.34.242 โ€“ Risk Score 80 (HIGH), Authority Score 70. This neighbor warrants separate investigation and monitoring.

---

## Historical Signal Analysis

Observation history shows 21 recorded signals from 2026-07-31 with stable characteristics:

---

## Recommended Actions

Firewall Rules (Block Recommendation)

iptables:

```

iptables -A INPUT -s 84.1.34.96 -j DROP

```

nftables:

```

nft add rule inet filter input ip saddr 84.1.34.96 drop

```

nginx:

```

deny 84.1.34.96;

```

pfSense:

```

84.1.34.96/32

```

Cloudflare WAF:

```json

{"description":"Block 84.1.34.96 โ€” IPDebrief risk score 50","action":"block","filter":{"expression":"ip.src eq 84.1.34.96"}}

```

AWS WAF:

```json

{"Addresses":["84.1.34.96/32"],"Description":"IPDebrief risk 50"}

```

---

## Intelligence Narrative

IP 84.1.34.96 is a static residential endpoint associated with Telekom Hungary's broadband infrastructure. The moderate risk score of 50 reflects its residential DSL classification and the presence of open SSH and HTTP services. The IP's DNS configuration is properly authenticated with SPF and DMARC records. While the address itself shows no active malicious indicators, its subnet neighbor (84.1.34.242) presents elevated risk.

The 2 DNSBL listings suggest historical association with potentially suspicious activity, though no current threat indicators are present. Route instability and basic operator scoring indicate this is not a critical infrastructure endpoint but rather a consumer-facing static IP.

Recommendation: Implement blocking at the perimeter layer with monitoring on the neighboring IP 84.1.34.242. The residential nature of this endpoint means false positive blocking may impact legitimate users, so consider time-based blocking or rate limiting rather than permanent drops if business continuity requirements exist.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ญ๐Ÿ‡บ Hungary
RegionBudapest
CityBudapest
TimezoneEurope/Budapest
Latitude47.16
Longitude19.50

๐Ÿข Ownership & Registration

OrganizationMTELEKOM-MNT
ASNAS5483
Network NameMT-BROADBAND-STATIC-DSL
CIDR Block84.1.34.0/23
RIRRIPE
CountryHU
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRdsl54012260.fixip.t-online.hu
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnamesdsl54012260.fixip.t-online.hu

๐Ÿ” DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeMulti-Service Host
Network TierTier 3 โ€” Basic operator with some routing infrastructure
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
22sshtcp
Closed Ports25, 443, 3389, 8080, 8443 (2 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”
SSH VersionSSH-2.0-ROSSSH

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
0%
00
reputation
0%
00
geolocation
25%
11
Overall16%44
Coverage: 4/6 dimensions ยท Data sufficiency: partial
Data CoherenceMostly Consistent (80%) โ€” 1 contradiction(s)
AttributionModerate (55%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Geo sources disagree on country: US, HU

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-07-29 22:50:53 UTC
Last Seen2026-08-13 06:45:22 UTC
Profile Built2026-08-10 17:30:11 UTC
Data FreshnessLive
Signal Types23
Total Observations24
๐Ÿ” 23 signal types ยท 24 observations collected
This report is generated from 23+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.