IPDebrief

88.20.35.254

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

## IP Intelligence Briefing: 88.20.35.254/32

Classification: Moderate Risk | Risk Score: 50

Executive Summary

IP 88.20.35.254 is a residential static IP assigned to Telefonica de Espana (ASN 3352) RIMA network infrastructure. The IP shows moderate risk (50) primarily due to DNSBL listings (2 of 8 lists) and geolocation inconsistencies. While the subnet neighborhood remains clean (0 abuse density), the IP warrants monitoring due to certificate misalignment and routing anomalies.

Technical Profile

Threat Indicators

Historical Observations

24 total observations recorded. Recent activity includes:

Neighborhood Context

Subnet 88.20.35.254/24 classification: clean

Recommended Actions

Firewall/Blocking Recommendations:

SOC Analyst Guidance:

1. Monitor TLS Certificate Mismatch: Certificate issued to traumapp.ddns.net does not align with expected host. Verify if this is intentional or indicates compromised infrastructure.

2. Track Geo Inconsistencies: One observation traced to US New York despite Spain registration. Investigate routing anomalies or spoofing attempts.

3. DNSBL Monitoring: IP listed on 2 of 8 DNSBLs. Confirm which lists and assess impact on reputation.

4. Residential IP Risk: Mobile carrier static IPs are commonly abused for spam/malware. Consider broader subnet monitoring.

5. Risk Score Context: Provider and authority scores are 0, indicating this is not a known malicious infrastructure but rather a misconfigured or compromised residential endpoint.

Conclusion

IP 88.20.35.254 represents a moderate-risk residential endpoint with DNSBL listings and certificate/host misalignment. The subnet environment is clean, suggesting isolated rather than coordinated activity. Recommended for monitoring and blocking if traffic patterns indicate abuse. No immediate evidence of active campaign participation.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ช๐Ÿ‡ธ Spain
RegionCL
CityArgujillo
TimezoneEurope/Madrid
Latitude37.99
Longitude-1.12

๐Ÿข Ownership & Registration

OrganizationAdministradores Telefonica de Espana
ASNAS3352
Network NameRIMA
CIDR Block88.16.0.0/13
RIRRIPE
CountryES
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR254.red-88-20-35.staticip.rima-tde.net
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnames254.red-88-20-35.staticip.rima-tde.net

๐Ÿ” DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureMobile
Service PurposeWeb Server
Network TierTier 3 โ€” Basic operator with some routing infrastructure
Mobile

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
443httpstcpโ€”
Closed Ports22, 25, 3389, 8080, 8443 (2 open / 7 scanned)
ServerApache/2.4.18 (Ubuntu)
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
CN=traumapp.ddns.net
Issued by CN=YR1, O=Let's Encrypt, C=US
Self-signed: No
SANstraumapp.ddns.net
Valid From2026-07-27T15:13:06+00:00
Valid Until2026-10-25T15:13:05+00:00
TLS ProtocolTls12
Cipher SuiteTLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period89 days
Serial Number053AF307C43136B837C50A4072A17B3385B3
Thumbprint4EF6773B5A44263F8707CFFC0829C44FF398EEEB

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
25%
12
reputation
0%
00
geolocation
35%
22
Overall22%67
Coverage: 5/6 dimensions ยท Data sufficiency: partial
Data CoherenceMostly Consistent (80%) โ€” 1 contradiction(s)
AttributionModerate (55%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Geo sources disagree on country: ES, US

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-07-30 23:21:06 UTC
Last Seen2026-08-04 18:00:12 UTC
Profile Built2026-07-31 05:29:57 UTC
Data FreshnessLive
Signal Types24
Total Observations25
๐Ÿ” 24 signal types ยท 25 observations collected
This report is generated from 24+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.