## IP Intelligence Briefing: 88.20.35.254/32
Classification: Moderate Risk | Risk Score: 50
Executive Summary
IP 88.20.35.254 is a residential static IP assigned to Telefonica de Espana (ASN 3352) RIMA network infrastructure. The IP shows moderate risk (50) primarily due to DNSBL listings (2 of 8 lists) and geolocation inconsistencies. While the subnet neighborhood remains clean (0 abuse density), the IP warrants monitoring due to certificate misalignment and routing anomalies.
Technical Profile
- Network: 88.20.35.254/24, RIMA (Telefonica de Espana)
- Geolocation: Spain (ES), Argujillo region; RIR: Ripe
- Infrastructure Type: Mobile Carrier (Movistar/LTE-5G) repurposed as web server
- DNS: 254.red-88-20-35.staticip.rima-tde.net (static residential IP)
- Services: HTTP/HTTPS on ports 80/443, Apache/2.4.18 (Ubuntu)
- TLS Certificate: Let's Encrypt issued to traumapp.ddns.net (certificate subject mismatch with host)
Threat Indicators
- DNSBL Listings: 2 of 8 blacklists (dnsblListedCount)
- GeoValidation: 5 probes, avg RTT 130.6ms; distance 1716.4km from probe location
- Control Plane: BGP prefix 88.20.0.0/16, isRouteStable: false
- Campaign Correlation: 0 correlated IPs, 0 CERT matches
Historical Observations
24 total observations recorded. Recent activity includes:
- Geolocation inconsistencies (Spain primary, US New York observed in one trace)
- HTTP 302 redirects with Apache server fingerprint
- No persistent threat indicators (threatPersistenceDays: 0)
Neighborhood Context
Subnet 88.20.35.254/24 classification: clean
- Total siblings: 5, Active: 4
- Abuse density: 0
- Sibling risk scores: 0, 15, 25, 25 (all low-medium)
- No high-risk neighbors detected
Recommended Actions
Firewall/Blocking Recommendations:
- `iptables -A INPUT -s 88.20.35.254 -j DROP`
- `nft add rule inet filter input ip saddr 88.20.35.254 drop`
- Cloudflare WAF: Block with expression `ip.src eq 88.20.35.254`
- AWS WAF: Add address `88.20.35.254/32`
SOC Analyst Guidance:
1. Monitor TLS Certificate Mismatch: Certificate issued to traumapp.ddns.net does not align with expected host. Verify if this is intentional or indicates compromised infrastructure.
2. Track Geo Inconsistencies: One observation traced to US New York despite Spain registration. Investigate routing anomalies or spoofing attempts.
3. DNSBL Monitoring: IP listed on 2 of 8 DNSBLs. Confirm which lists and assess impact on reputation.
4. Residential IP Risk: Mobile carrier static IPs are commonly abused for spam/malware. Consider broader subnet monitoring.
5. Risk Score Context: Provider and authority scores are 0, indicating this is not a known malicious infrastructure but rather a misconfigured or compromised residential endpoint.
Conclusion
IP 88.20.35.254 represents a moderate-risk residential endpoint with DNSBL listings and certificate/host misalignment. The subnet environment is clean, suggesting isolated rather than coordinated activity. Recommended for monitoring and blocking if traffic patterns indicate abuse. No immediate evidence of active campaign participation.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Administradores Telefonica de Espana |
| ASN | AS3352 |
| Network Name | RIMA |
| CIDR Block | 88.16.0.0/13 |
| RIR | RIPE |
| Country | ES |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 254.red-88-20-35.staticip.rima-tde.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | 254.red-88-20-35.staticip.rima-tde.net |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | Apache/2.4.18 (Ubuntu) |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | traumapp.ddns.net |
| Valid From | 2026-07-27T15:13:06+00:00 |
| Valid Until | 2026-10-25T15:13:05+00:00 |
| TLS Protocol | Tls12 |
| Cipher Suite | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 89 days |
| Serial Number | 053AF307C43136B837C50A4072A17B3385B3 |
| Thumbprint | 4EF6773B5A44263F8707CFFC0829C44FF398EEEB |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 35% | 2 | 2 |
| Overall | 22% | 6 | 7 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-30 23:21:06 UTC |
| Last Seen | 2026-08-04 18:00:12 UTC |
| Profile Built | 2026-07-31 05:29:57 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 25 |
Full dossier details are available via our API.