IPDebrief

84.208.160.159

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# INTELLIGENCE BRIEFING: 84.208.160.159/32

Classification: LOW RISK / RESIDENTIAL CABLE NETWORK

Date: 2026-07-27

---

## Executive Summary

IP address 84.208.160.159 is a low-risk residential cable connection owned by GET-MNT under the OSLO-CUSTOMERS-CABLE network block (84.208.160.0/20). The IP shows no malicious activity indicators, no blacklist listings, and operates in a clean neighborhood with zero abuse density. Recommended action: Monitor but no immediate blocking required.

---

## Ownership & Network Context

AttributeValue
**ASN**25400
**Organization**GET-MNT / OSLO-CUSTOMERS-CABLE
**RIR**RIPE
**Country**Norway (NO)
**City/Region**Oslo
**CIDR Block**84.208.160.0/20
**Geolocation Confidence**52% (multi-signal inference)

The IP resolves to `cm-84.208.160.159.get.no`, indicating a cable modem customer premise device. Network routing shows the IP originates from BGP prefix 84.208.128.0/17 with origin ASN 25400.

---

## Risk Assessment

Overall Risk Score: 15/100 (Low Risk)

MetricScoreStatus
Provider Risk0Clean
Authority Risk0Clean
Stability0N/A
Blacklist Count0Clean
DNSBL Listed1/8Minimal
Abuse ConfidenceN/AN/A

Threat Indicators: None detected. IP is not flagged as Tor exit node, known attacker, spam source, or associated with any known campaigns.

---

## Network Behavior

IndicatorFinding
Service ClassificationFirewalled / No Services
Open PortsNone detected
Cloud/CDN/ProxyNo
ResidentialYes
Mobile CarrierNo
AnycastNo

The IP shows no active services or open ports, consistent with residential cable infrastructure. Control plane analysis indicates DNSSEC is valid, though the IP is listed on 1 of 8 DNSBLs (likely benign residential listing).

---

## Neighborhood Analysis

Subnet: 84.208.160.159/24

MetricValue
Abuse Density0%
ClassificationClean
Total Siblings1
Threat Siblings0
Active Siblings0

The /24 subnet demonstrates clean characteristics with no abuse activity detected across sibling addresses.

---

## Observation History

Total Observations: 18

Key findings from recent signal collection:

---

## Related Entities

DNS Associations:

Network Relationships:

---

## Recommended Actions

SOC Analyst Actions:

1. Monitor - Continue passive monitoring; no immediate threat indicators

2. No Blocking Required - Risk profile indicates legitimate residential use

3. Email Reputation - Domain (get.no) has SPF and DMARC configured

4. Firewall Rules - No specific rules recommended

If traffic originates from this IP:

---

Report Generated: 2026-07-27

Data Sources: IPDebrief Intelligence Platform

Classification: INTERNAL USE ONLY

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇳🇴 Norway
Region03
CityOslo
TimezoneEurope/Oslo
Latitude59.91
Longitude10.74

🏢 Ownership & Registration

OrganizationGET-MNT
ASNAS25400
Network NameOSLO-CUSTOMERS-CABLE
CIDR Block84.208.160.0/20
RIRRIPE
CountryNO
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRcm-84.208.160.159.get.no
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamescm-84.208.160.159.get.no

🔐 DNS Hygiene

Hygiene Score60% (Good)
SPFPresent
DMARCPresent
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown — Insufficient routing data to classify
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Server—
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS25400
Network Prefix84.208.128.0/17
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
23%
24
routing
8%
11
services
12%
22
ownership
23%
24
reputation
20%
13
geolocation
17%
23
Overall17%1017
Coverage: 6/6 dimensions · Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

📅 Observation Timeline 🔄 Live

First Seen2026-07-13 15:25:21 UTC
Last Seen2026-09-05 14:37:43 UTC
Profile Built2026-09-05 14:39:39 UTC
Data FreshnessLive
Signal Types24
Total Observations28
🔍 24 signal types · 28 observations collected
This report is generated from 24+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 84.208.160.159

Who owns the IP address 84.208.160.159?

84.208.160.159 is registered to GET-MNT. The address falls within the 84.208.160.0/20 network block. Registration is held at RIPE.

Where is 84.208.160.159 located?

Geolocation data places 84.208.160.159 in Oslo, 03, Norway. The local time zone is Europe/Oslo. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 84.208.160.159 malicious or safe?

84.208.160.159 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.

What is the hostname for 84.208.160.159?

The reverse DNS (PTR) record for 84.208.160.159 is cm-84.208.160.159.get.no. This hostname is not forward-confirmed, so it should be treated as a weak signal.

🏘️ Related IP Addresses

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.