# IP Intelligence Briefing: 84.54.73.4
## Executive Summary
IP address 84.54.73.4 is classified as High Risk (Risk Score: 80/100) with elevated threat indicators requiring immediate attention. The IP belongs to UZTELECOM (ASN 8193, Role of Uzbektelecom JSC) and is geolocated to Tashkent, Uzbekistan. Despite showing no open services, the IP demonstrates significant abuse indicators and should be blocked at perimeter infrastructure.
## Risk Assessment
Risk Score: 80/100 (High Risk)
Threat Indicators:
- DNSBL Listed Count: 5 of 8 total threat feeds
- Operator Score: 0.1304 (Minimal operator risk)
- No active services detected (firewalled/no services)
- No current threat indicators or known campaigns associated
- Not classified as Tor exit, proxy, or known attacker
Ownership & Registration:
- ASN: 8193
- Organization: Role of Uzbektelecom JSC
- Network: UZTELECOM (84.54.73.0/24)
- RIR: RIPE
- Geolocation: Uzbekistan, Tashkent
## Network Context
Neighborhood Analysis (84.54.73.0/24):
- Total Siblings: 18
- Active Siblings: 3
- Threat Siblings: 2
- Abuse Density: 0.353
- Risk Distribution: 6 High Risk, 10 Medium Risk, 0 Low Risk
The subnet shows concentrated risk with multiple high-scoring neighbors. This IP shares network infrastructure with 6 other high-risk addresses in the /24 block.
DNS Relationships:
- PTR Hostname: 4.73.intal.uz
- Forward Resolution: Not confirmed
- Associated Domain: intal.uz
- No SPF/DMARC records configured
## Behavioral Observations
Observation History: 12 signals recorded
- Recent observations (2026-07-31) confirm consistent ASN and geolocation data
- No persistent malicious behavior detected
- Threat persistence days: 0
- No ownership changes recorded
Services: No open ports or HTTP services detected. The IP appears firewalled or configured for non-public-facing services.
## Recommended Actions
Immediate Actions Required:
1. Block at Perimeter: Implement firewall rules to drop traffic from 84.54.73.4/32
2. Increase Logging: Enable enhanced logging verbosity for this IP to capture any attempted connections
3. Monitor Related IPs: Review activity from 6 other high-risk neighbors in the same /24 subnet
Firewall Rules:
- iptables: `iptables -A INPUT -s 84.54.73.4 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 84.54.73.4 drop`
- nginx: `deny 84.54.73.4;`
- pfSense: `84.54.73.4/32`
- Cloudflare WAF: Block with expression `ip.src eq 84.54.73.4`
- AWS WAF: Add to block list with CIDR 84.54.73.4/32
## Intelligence Narrative
This IP address presents elevated risk despite lacking active service exposure. The high-risk classification stems primarily from DNSBL listings (5 of 8 feeds) and neighborhood context within a subnet showing 35.3% abuse density. The UZTELECOM network has a reputation for hosting legitimate infrastructure, but this specific /24 block contains multiple high-risk addresses. The DNS association with intal.uz and PTR record 4.73.intal.uz suggests the IP may have been used for email services or similar applications at some point.
Recommendation: Treat as malicious traffic source. Block at perimeter firewall and implement enhanced logging. Given the subnet-wide risk concentration, consider evaluating the entire 84.54.73.0/24 block for traffic filtering based on organizational policy.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Role of Uzbektelecom JSC |
| ASN | AS8193 |
| Network Name | UZTELECOM |
| CIDR Block | 84.54.73.0/24 |
| RIR | RIPE |
| Country | UZ |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 4.73.intal.uz |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 4.73.intal.uz |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Residential |
| Service Purpose | Residential Endpoint |
| Network Tier | End-User β Residential ISP endpoint |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 45% | 2 | 3 |
| routing | 22% | 1 | 1 |
| services | 31% | 2 | 2 |
| ownership | 45% | 2 | 3 |
| reputation | 22% | 1 | 2 |
| geolocation | 0% | 0 | 0 |
| Overall | 27% | 8 | 11 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-29 22:50:53 UTC |
| Last Seen | 2026-07-31 19:33:26 UTC |
| Profile Built | 2026-07-31 13:33:10 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 21 |
Full dossier details are available via our API.