# INTELLIGENCE BRIEFING: 84.54.70.214/32
## EXECUTIVE SUMMARY
IP address 84.54.70.214 presents as a High Risk (80/100) residential endpoint within the UZTELECOM network infrastructure. Despite official geolocation data indicating Amsterdam, NL, the subnet exhibits elevated abuse density (0.393) with 11 high-risk and 16 medium-risk siblings. The IP is classified as residential with no active services detected.
## INFRASTRUCTURE PROFILE
| Attribute | Value |
|---|---|
| **IP Address** | 84.54.70.214/32 |
| **Risk Score** | 80 (High Risk) |
| **Organization** | Role of Uzbektelecom JSC |
| **ASN** | 8193 |
| **CIDR Block** | 84.54.70.0/24 |
| **RIR** | RIPE |
| **Network Role** | Residential Endpoint |
| **DNS Reverse** | 214.70.albatros.uz |
| **DNS Domain** | albatros.uz |
## GEOLOCATION INTELLIGENCE
Geolocation data presents conflicting signals. The profile indicates Amsterdam, NL, while historical observations show Uzbekistan/Tashkent associations. Traceroute analysis revealed 30 hops with 17 timed-out hops through Comcast transit networks. Geo validation flags indicate a plausible geolocation violation. This discrepancy suggests either misconfigured reverse DNS or the IP's use in multi-tenant residential infrastructure.
## THREAT INDICATORS
- Blacklist Count: 0
- DNSBL Listed: 6 of 8 total lists
- Tor Exit: False
- Known Attacker: False
- Spam Source: False
- Threat Feeds: None populated
- Campaign Correlation: No matches detected
## NETWORK CLASSIFICATION
- Infrastructure Type: Residential
- Connection Type: Not specified
- Cloud/CDN/VPN/Proxy: All false
- Hosting/Anycast/Mobile: All false
- Bogon: False
## SUBNET ANALYSIS (84.54.70.0/24)
| Metric | Value |
|---|---|
| **Total Siblings** | 29 |
| **Active Siblings** | 6 |
| **Abuse Density** | 0.393 |
| **Risk Distribution** | 11 High, 16 Medium, 1 Low |
| **Classification** | Mostly Clean |
The subnet demonstrates concerning abuse patterns with 38% of neighbors flagged as high or medium risk. Notable high-risk neighbors include 84.54.70.3, 84.54.70.11, 84.54.70.17, and 84.54.70.21 (all scoring 80).
## OBSERVATION HISTORY
15 observations recorded as of July 31, 2026. Key signals include:
- Geolocation: Amsterdam, NL (confidence: 0.70)
- ASN/ORG: Ripe, UZTELECOM, Role of Uzbektelecom JSC (confidence: 0.90-0.95)
- Network Role: Residential (confidence: 0.40)
The IP demonstrates threat persistence of 0 days with no persistent malicious classification.
## RELATIONSHIP GRAPH
Six relationships identified:
- Same Network: UZTELECOM (3x instances)
- DNS Association: 214.70.albatros.uz (3x instances)
## RECOMMENDED ACTIONS
1. Block at perimeter firewall if the IP exhibits outbound connections or inbound scanning activity
2. Monitor for pattern matching with high-risk siblings in the /24 subnet
3. Review DNS records for albatros.uz to verify legitimate ownership
4. Add to blocklist if associated with malicious traffic patterns
## ANALYST NOTES
The combination of high risk score, residential classification, and subnet abuse density warrants heightened monitoring. The geolocation discrepancy between Amsterdam and Uzbekistan data suggests potential infrastructure misconfiguration or multi-tenant residential hosting. The IP's 6 DNSBL listings despite zero blacklist count indicates potential false positives or domain-level reputation issues.
---
*Report generated: Current date*
*Classification: SOC Intelligence*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Role of Uzbektelecom JSC |
| ASN | AS8193 |
| Network Name | UZTELECOM |
| CIDR Block | 84.54.70.0/24 |
| RIR | RIPE |
| Country | UZ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 214.70.albatros.uz |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 214.70.albatros.uz |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Residential |
| Service Purpose | Residential Endpoint |
| Network Tier | End-User โ Residential ISP endpoint |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 45% | 2 | 3 |
| routing | 22% | 1 | 1 |
| services | 31% | 2 | 2 |
| ownership | 45% | 2 | 3 |
| reputation | 22% | 1 | 2 |
| geolocation | 0% | 0 | 0 |
| Overall | 27% | 8 | 11 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-29 22:50:53 UTC |
| Last Seen | 2026-07-31 13:32:51 UTC |
| Profile Built | 2026-07-31 13:33:10 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 21 |
Full dossier details are available via our API.