# IP Intelligence Briefing: 91.38.116.136
Date: Current Analysis Cycle
Classification: DEFCON 4 / LOW THREAT
Analysis Period: All Available Historical Data
---
## Executive Summary
IP address 91.38.116.136 is a low-risk residential/mobile endpoint associated with Deutsche Telekom's infrastructure. The IP demonstrates no active malicious behavior, no open services, and operates within a clean network neighborhood. Recommended handling: Monitor but no immediate blocking required.
---
## Technical Profile
| Attribute | Value |
|---|---|
| **IP Address** | 91.38.116.136/32 |
| **Risk Score** | 25 / 100 (Low Risk) |
| **ASN** | 3320 |
| **Organization** | DTAG-NIC / DTAG-DIAL23 |
| **Network Block** | 91.32.0.0/11 |
| **Country** | DE (Germany) |
| **Region/City** | Bavaria, Regensburg |
| **Mobile Carrier** | Telekom / Deutsche Telekom AG (MCC: 262, MNC: 01) |
| **Connection Type** | LTE/5G Mobile |
| **Infrastructure Type** | Residential Mobile Endpoint |
---
## Network Classification
- Provider Status: Null (End-user allocation)
- Cloud/CDN/Proxy: Negative on all indicators
- Tor Exit Node: False
- Known Attacker: False
- Spam Source: False
- DNSBL Listed: 1 of 8 total lists
- Open Ports: None detected
- Service Status: Firewalled / No Services
DNS Resolution: p5b267488.dip0.t-ipconnect.de (t-ipconnect.de)
PTR Record: Forward resolution confirmed
---
## Threat Indicators
| Indicator | Status |
|---|---|
| **Abuse Confidence Score** | Not Calculated |
| **Blacklist Count** | 0 |
| **Pulsedive Risk** | Not Available |
| **Known Campaigns** | None |
| **Threat Persistence Days** | 0 |
| **Persistently Malicious** | False |
Threat Evidence: No threat indicators detected. No correlation to known attack campaigns.
---
## Neighborhood Analysis (91.38.116.0/24)
- Subnet Classification: Clean
- Abuse Density: 0.0
- Total Siblings: 1
- Active Threat Siblings: 0
- High Risk Neighbors: 0
- Medium Risk Neighbors: 0
- Low Risk Neighbors: 0
---
## Historical Observations
Total Signals: 19 observations
Recent Activity Summary:
- Port Scans: Detected (2026-07-29)
- Traceroute Attempts: Detected (2026-07-29)
- Geolocation Inference: DE (51.17, 10.45) - 400km accuracy
- Ownership Changes: 0
- Threat Observations: 0
Temporal Analysis:
- Ownership stability: High (no changes)
- Threat persistence: None detected
- Pattern: Passive residential endpoint with standard scanning activity
---
## Control Plane Analysis
- BGP Prefix: 91.0.0.0/10
- Route Stability: False
- RPKI State: Not Available
- IRR Consistency: Not Available
- Route Changes (30d): 0
- DNSSEC Valid: True
- Operator Score: 0.2609 (Basic)
---
## Relationships
DNS Associations:
- p5b267488.dip0.t-ipconnect.de (repeated association)
Network Associations:
- DTAG-DIAL23 (same network)
No external entity correlations detected.
---
## Recommended Security Actions
Risk-Based Recommendations: NONE
Justification:
- Risk score of 25 indicates low threat level
- No malicious indicators or campaigns detected
- Clean subnet neighborhood (0 abuse density)
- No active services or port exposure
- Legitimate Deutsche Telekom mobile infrastructure
Firewall Rules: Not required at this time
Monitoring Priority: Standard
---
## Intelligence Assessment
This IP address represents a legitimate residential/mobile endpoint within Deutsche Telekom's network infrastructure. The absence of open services, combined with the clean subnet classification and zero malicious indicators, suggests normal residential internet usage. The single DNSBL listing appears to be a false positive or outdated entry.
Threat Level: LOW
Recommended Action: Allow with standard logging
Investigation Priority: None
---
*Intelligence produced by IPDebrief analysis tools. Data accuracy based on available signal sources and confidence levels.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | DTAG-NIC |
| ASN | AS3320 |
| Network Name | DTAG-DIAL23 |
| CIDR Block | 91.32.0.0/11 |
| RIR | RIPE |
| Country | DE |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | p5b267488.dip0.t-ipconnect.de |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | p5b267488.dip0.t-ipconnect.de |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-21 12:55:54 UTC |
| Last Seen | 2026-07-29 09:44:06 UTC |
| Profile Built | 2026-07-29 09:58:25 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 22 |
Full dossier details are available via our API.