# IP Intelligence Briefing: 91.40.150.83/32
## Executive Summary
IP 91.40.150.83 presents a Low Risk profile (Risk Score: 25/100) with no active malicious indicators. Intelligence indicates this is a residential/mobile consumer IP address from Deutsche Telekom's T-IPConnect dynamic IP service. No immediate threat action recommended.
## Threat Assessment
- Risk Classification: Low Risk (25/100)
- Known Attacker: No
- Tor Exit Node: No
- Known Spam Source: No
- Blacklist Status: 0 blacklist listings
- Abuse Confidence Score: Not applicable
- Threat Persistence: No persistent malicious activity observed
## Network Ownership & Infrastructure
| Attribute | Value |
|---|---|
| **ASN** | 3320 (DTAG-NIC) |
| **Organization** | DTAG-DIAL23 |
| **Network Range** | 91.32.0.0/11 |
| **RIR** | RIPE |
| **Registration Date** | Not available |
## Geolocation Data
- Country: Germany (DE)
- Region: Brandenburg
- City: Lauchhammer
- Coordinates: 51.17°N, 10.45°E
- Timezone: Europe/Berlin
- Geo Confidence: High (consensus validation confirmed)
## Network Role Classification
- Connection Type: Mobile (LTE/5G)
- Mobile Carrier: Telekom (Deutsche Telekom AG)
- Technology: LTE/5G
- MCC/MNC: 262/01
- Infrastructure Type: Residential Consumer
- Services: Firewalled / No Services Detected
## DNS Analysis
- PTR Hostname: p5b289653.dip0.t-ipconnect.de
- Domain: t-ipconnect.de
- Forward Resolution: Confirmed (1 hostname)
- Email Authentication: SPF/DMARC not configured
- DNSSEC Valid: Yes
- DNSBL Listings: 1 of 8 total lists
## Neighborhood Analysis (91.40.150.0/24)
- Abuse Density: 0 (Clean)
- Classification: Clean
- Total Siblings: 2
- Active Siblings: 1
- Threat Siblings: 0
- Sibling Risk Profile: 1 neighbor (91.40.150.244) with Medium Risk (40/100)
## Control Plane Observations
- Origin ASN: 3320
- BGP Prefix: 91.0.0.0/10
- Route Stability: Unstable (changes detected in 30-day period)
- Route Changes: 0
- MOAS Status: Not identified
- IRR Consistency: Not available
## Historical Signals (18 Observations)
Recent observations indicate:
- Traceroute probes reaching target (30 hops)
- Network classification signals (mobile/residential)
- Geolocation inferences (DE, Brandenburg region)
- Subnet abuse density assessments (clean classification)
- No persistent threat indicators observed
## Relationships Graph
- Same Network: DTAG-DIAL23 (multiple associations)
- DNS Association: p5b289653.dip0.t-ipconnect.de
- No External Certificates: None
- No Cross-Organization Links: Confined to single network
## Recommended Security Actions
- Firewall Rules: No specific rules generated (Low Risk profile)
- Monitoring: No additional monitoring required
- Block Recommendation: Not recommended
- Note: IP classified as residential/mobile consumer traffic
## Intelligence Narrative
IP 91.40.150.83 is a Deutsche Telekom residential IP address from the T-IPConnect dynamic IP service. The address exhibits standard mobile consumer characteristics with no malicious activity patterns. The subnet demonstrates clean abuse density with minimal threat indicators. One neighboring IP (91.40.150.244) shows elevated risk (40/100), suggesting potential localized network activity that warrants awareness but not action against the primary subject.
Route instability flags may indicate BGP propagation changes rather than malicious activity. The single DNSBL listing is consistent with dynamic residential IP reputation profiles.
Conclusion: This IP address represents legitimate consumer traffic. No threat-based action required. Standard monitoring practices apply.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | DTAG-NIC |
| ASN | AS3320 |
| Network Name | DTAG-DIAL23 |
| CIDR Block | 91.32.0.0/11 |
| RIR | RIPE |
| Country | DE |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | p5b289653.dip0.t-ipconnect.de |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | p5b289653.dip0.t-ipconnect.de |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 4% | 1 | 2 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-22 19:33:34 UTC |
| Last Seen | 2026-07-29 15:45:44 UTC |
| Profile Built | 2026-07-29 15:58:11 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 20 |
Full dossier details are available via our API.