# INTELLIGENCE BRIEFING: 84.208.160.159/32
Classification: LOW RISK / RESIDENTIAL CABLE NETWORK
Date: 2026-07-27
---
## Executive Summary
IP address 84.208.160.159 is a low-risk residential cable connection owned by GET-MNT under the OSLO-CUSTOMERS-CABLE network block (84.208.160.0/20). The IP shows no malicious activity indicators, no blacklist listings, and operates in a clean neighborhood with zero abuse density. Recommended action: Monitor but no immediate blocking required.
---
## Ownership & Network Context
| Attribute | Value |
|---|---|
| **ASN** | 25400 |
| **Organization** | GET-MNT / OSLO-CUSTOMERS-CABLE |
| **RIR** | RIPE |
| **Country** | Norway (NO) |
| **City/Region** | Oslo |
| **CIDR Block** | 84.208.160.0/20 |
| **Geolocation Confidence** | 52% (multi-signal inference) |
The IP resolves to `cm-84.208.160.159.get.no`, indicating a cable modem customer premise device. Network routing shows the IP originates from BGP prefix 84.208.128.0/17 with origin ASN 25400.
---
## Risk Assessment
Overall Risk Score: 15/100 (Low Risk)
| Metric | Score | Status |
|---|---|---|
| Provider Risk | 0 | Clean |
| Authority Risk | 0 | Clean |
| Stability | 0 | N/A |
| Blacklist Count | 0 | Clean |
| DNSBL Listed | 1/8 | Minimal |
| Abuse Confidence | N/A | N/A |
Threat Indicators: None detected. IP is not flagged as Tor exit node, known attacker, spam source, or associated with any known campaigns.
---
## Network Behavior
| Indicator | Finding |
|---|---|
| Service Classification | Firewalled / No Services |
| Open Ports | None detected |
| Cloud/CDN/Proxy | No |
| Residential | Yes |
| Mobile Carrier | No |
| Anycast | No |
The IP shows no active services or open ports, consistent with residential cable infrastructure. Control plane analysis indicates DNSSEC is valid, though the IP is listed on 1 of 8 DNSBLs (likely benign residential listing).
---
## Neighborhood Analysis
Subnet: 84.208.160.159/24
| Metric | Value |
|---|---|
| Abuse Density | 0% |
| Classification | Clean |
| Total Siblings | 1 |
| Threat Siblings | 0 |
| Active Siblings | 0 |
The /24 subnet demonstrates clean characteristics with no abuse activity detected across sibling addresses.
---
## Observation History
Total Observations: 18
Key findings from recent signal collection:
- Geolocation consistently indicates Oslo, Norway (60.47°N, 8.47°E)
- Operator score: Minimal (0.1304)
- Geo validation: Plausible but ICMP blocked (867.7 km distance from probe)
- No ownership changes observed
- No threat persistence detected
- Not classified as persistently malicious
---
## Related Entities
DNS Associations:
- cm-84.208.160.159.get.no (3 associations)
Network Relationships:
- OSLO-CUSTOMERS-CABLE (3 associations)
---
## Recommended Actions
SOC Analyst Actions:
1. Monitor - Continue passive monitoring; no immediate threat indicators
2. No Blocking Required - Risk profile indicates legitimate residential use
3. Email Reputation - Domain (get.no) has SPF and DMARC configured
4. Firewall Rules - No specific rules recommended
If traffic originates from this IP:
- Verify against local threat intel feeds
- Consider geographic context if traffic patterns appear anomalous
- No action needed for standard business traffic
---
Report Generated: 2026-07-27
Data Sources: IPDebrief Intelligence Platform
Classification: INTERNAL USE ONLY
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | GET-MNT |
| ASN | AS25400 |
| Network Name | OSLO-CUSTOMERS-CABLE |
| CIDR Block | 84.208.160.0/20 |
| RIR | RIPE |
| Country | NO |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | cm-84.208.160.159.get.no |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | cm-84.208.160.159.get.no |
🔐 DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS25400 |
| Network Prefix | 84.208.128.0/17 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 23% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 23% | 2 | 4 |
| reputation | 20% | 1 | 3 |
| geolocation | 17% | 2 | 3 |
| Overall | 17% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-13 15:25:21 UTC |
| Last Seen | 2026-09-05 14:37:43 UTC |
| Profile Built | 2026-09-05 14:39:39 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 28 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 84.208.160.159
Who owns the IP address 84.208.160.159?
84.208.160.159 is registered to GET-MNT. The address falls within the 84.208.160.0/20 network block. Registration is held at RIPE.
Where is 84.208.160.159 located?
Geolocation data places 84.208.160.159 in Oslo, 03, Norway. The local time zone is Europe/Oslo. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 84.208.160.159 malicious or safe?
84.208.160.159 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 84.208.160.159?
The reverse DNS (PTR) record for 84.208.160.159 is cm-84.208.160.159.get.no. This hostname is not forward-confirmed, so it should be treated as a weak signal.