IPDebrief

84.54.70.214

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# INTELLIGENCE BRIEFING: 84.54.70.214/32

## EXECUTIVE SUMMARY

IP address 84.54.70.214 presents as a High Risk (80/100) residential endpoint within the UZTELECOM network infrastructure. Despite official geolocation data indicating Amsterdam, NL, the subnet exhibits elevated abuse density (0.393) with 11 high-risk and 16 medium-risk siblings. The IP is classified as residential with no active services detected.

## INFRASTRUCTURE PROFILE

AttributeValue
**IP Address**84.54.70.214/32
**Risk Score**80 (High Risk)
**Organization**Role of Uzbektelecom JSC
**ASN**8193
**CIDR Block**84.54.70.0/24
**RIR**RIPE
**Network Role**Residential Endpoint
**DNS Reverse**214.70.albatros.uz
**DNS Domain**albatros.uz

## GEOLOCATION INTELLIGENCE

Geolocation data presents conflicting signals. The profile indicates Amsterdam, NL, while historical observations show Uzbekistan/Tashkent associations. Traceroute analysis revealed 30 hops with 17 timed-out hops through Comcast transit networks. Geo validation flags indicate a plausible geolocation violation. This discrepancy suggests either misconfigured reverse DNS or the IP's use in multi-tenant residential infrastructure.

## THREAT INDICATORS

## NETWORK CLASSIFICATION

## SUBNET ANALYSIS (84.54.70.0/24)

MetricValue
**Total Siblings**29
**Active Siblings**6
**Abuse Density**0.393
**Risk Distribution**11 High, 16 Medium, 1 Low
**Classification**Mostly Clean

The subnet demonstrates concerning abuse patterns with 38% of neighbors flagged as high or medium risk. Notable high-risk neighbors include 84.54.70.3, 84.54.70.11, 84.54.70.17, and 84.54.70.21 (all scoring 80).

## OBSERVATION HISTORY

15 observations recorded as of July 31, 2026. Key signals include:

The IP demonstrates threat persistence of 0 days with no persistent malicious classification.

## RELATIONSHIP GRAPH

Six relationships identified:

## RECOMMENDED ACTIONS

1. Block at perimeter firewall if the IP exhibits outbound connections or inbound scanning activity

2. Monitor for pattern matching with high-risk siblings in the /24 subnet

3. Review DNS records for albatros.uz to verify legitimate ownership

4. Add to blocklist if associated with malicious traffic patterns

## ANALYST NOTES

The combination of high risk score, residential classification, and subnet abuse density warrants heightened monitoring. The geolocation discrepancy between Amsterdam and Uzbekistan data suggests potential infrastructure misconfiguration or multi-tenant residential hosting. The IP's 6 DNSBL listings despite zero blacklist count indicates potential false positives or domain-level reputation issues.

---

*Report generated: Current date*

*Classification: SOC Intelligence*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ณ๐Ÿ‡ฑ Netherlands
RegionUzbekistan
CityAmsterdam
TimezoneEurope/Amsterdam
Latitude52.37
Longitude4.89

๐Ÿข Ownership & Registration

OrganizationRole of Uzbektelecom JSC
ASNAS8193
Network NameUZTELECOM
CIDR Block84.54.70.0/24
RIRRIPE
CountryUZ
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR214.70.albatros.uz
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnames214.70.albatros.uz

๐Ÿ” DNS Hygiene

Hygiene Score40% (Fair)
SPFPresent
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureResidential
Service PurposeResidential Endpoint
Network TierEnd-User โ€” Residential ISP endpoint
Residential

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
45%
23
routing
22%
11
services
31%
22
ownership
45%
23
reputation
22%
12
geolocation
0%
00
Overall27%811
Coverage: 3/6 dimensions ยท Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-07-29 22:50:53 UTC
Last Seen2026-07-31 13:32:51 UTC
Profile Built2026-07-31 13:33:10 UTC
Data FreshnessLive
Signal Types19
Total Observations21
๐Ÿ” 19 signal types ยท 21 observations collected
This report is generated from 19+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.