# IPDEBRIEF INTELLIGENCE BRIEFING
Target: 84.161.221.144/32
Date: 2026-07-31
Classification: MODERATE RISK
---
## EXECUTIVE SUMMARY
IP 84.161.221.144 presents a moderate risk profile (Score: 50) associated with Deutsche Telekom mobile infrastructure. The IP is classified as a mobile device connection from Trier, Germany, with no active service ports or known threat indicators. Geographic validation discrepancies observed in historical data warrant monitoring.
---
## OWNERSHIP & INFRASTRUCTURE
- ASN: 3320 (DTAG-NIC)
- Organization: DTAG-DIAL20 (Deutsche Telekom)
- CIDR Block: 84.136.0.0/13
- Geolocation: Trier, Rheinland-Pfalz, Germany (51.17°N, 10.45°E)
- Mobile Carrier: Telekom (Deutsche Telekom AG)
- Connection Technology: LTE/5G
- Network Classification: Mobile Device, Firewalled/No Services
- Infrastructure Type: Not CDN, Cloud, VPN, or Proxy
---
## THREAT ASSESSMENT
| Indicator | Status |
|---|---|
| Risk Score | 50 (Moderate) |
| Is Tor Exit Node | No |
| Is Known Attacker | No |
| Is Spam Source | No |
| Blacklist Count | 0 |
| DNSBL Listed | 2 of 8 lists |
| Known Campaigns | None |
| Operator Score | 0.2609 (Basic) |
Threat Indicators: Empty. No active threat feeds or campaign associations detected.
---
## OBSERVATION HISTORY
- Total Observations: 19 signals
- Last Observed: 2026-07-31T00:31:48 UTC
- Threat Persistence: 0 days (not persistently malicious)
Key Historical Events:
- 2026-07-31 00:31:48 UTC: Geolocation validated at Trier, Germany (Confidence: 0.50)
- 2026-07-31 00:27:45 UTC: Anomalous geolocation detected at New York, US (Confidence: 0.80) โ *Potential false positive or routing anomaly*
- ICMP Validation: Blocked โ unable to validate
- Service Scanning: No open ports, no TLS certificates, no HTTP services detected
---
## RELATIONSHIP ANALYSIS
- DNS Associations: p54a1dd90.dip0.t-ipconnect.de (T-IPConnect German residential proxy service)
- Network Associations: DTAG-DIAL20
- Related Entities: 8 relationship links (all DNS or network associations)
---
## NEIGHBORHOOD ANALYSIS
- Subnet: 84.161.221.144/24
- Abuse Density: 0
- Subnet Classification: Clean
- Active Siblings: 0
- Threat Siblings: 0
- Risk Distribution: No high-risk neighbors detected
---
## RECOMMENDED ACTIONS
Firewall Rules:
- iptables: `iptables -A INPUT -s 84.161.221.144 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 84.161.221.144 drop`
- nginx: `deny 84.161.221.144;`
- pfSense: Add 84.161.221.144/32 to block list
- Cloudflare WAF: Block expression: `ip.src eq 84.161.221.144`
- AWS WAF: Add 84.161.221.144/32 to IP set
Note: These recommendations are probabilistic. Combine with other signals before taking action.
---
## ANALYST NOTES
The IP address is associated with Deutsche Telekom mobile infrastructure and resolves to a T-IPConnect hostname (German residential proxy service). While currently showing moderate risk, the absence of active threat indicators, empty threat feeds, and clean neighborhood suggests this IP is not actively malicious.
Key Observations:
1. Geographic discrepancy between Trier, DE (profile) and New York, US (history) requires investigation
2. No open ports or services detected โ likely a consumer mobile device
3. 2/8 DNSBL listings indicate some reputation concerns
4. BGP prefix stability is false โ routing changes may be occurring
Recommendation: Monitor for increased activity or geolocation anomalies. No immediate blocking required unless contextual threat intelligence indicates otherwise.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | DTAG-NIC |
| ASN | AS3320 |
| Network Name | DTAG-DIAL20 |
| CIDR Block | 84.136.0.0/13 |
| RIR | RIPE |
| Country | DE |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | p54a1dd90.dip0.t-ipconnect.de |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | p54a1dd90.dip0.t-ipconnect.de |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 45% | 2 | 3 |
| routing | 22% | 1 | 1 |
| services | 31% | 2 | 2 |
| ownership | 45% | 2 | 3 |
| reputation | 22% | 1 | 2 |
| geolocation | 45% | 2 | 3 |
| Overall | 35% | 10 | 14 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-29 22:50:53 UTC |
| Last Seen | 2026-07-31 13:32:51 UTC |
| Profile Built | 2026-07-31 13:33:11 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 24 |
Full dossier details are available via our API.