# IP Intelligence Briefing: 95.10.12.162/32
Date: 2026-07-30
Classification: Moderate Risk (Score: 40)
Status: Operational Monitoring
---
## Executive Summary
IP 95.10.12.162 is a mobile residential endpoint registered to TurkTelekom (ASN 9121) in Turkey. The IP demonstrates moderate risk primarily due to DNSBL listings but lacks active threat indicators. No malicious campaigns, scanning activity, or peer exploitation observed within the subnet.
---
## Network & Geographic Context
| Attribute | Value |
|---|---|
| **Country** | Turkey (TR) |
| **City** | Konyaalti, Antalya |
| **ASN** | 9121 (TurkTelekom) |
| **Network** | 95.10.0.0/16 |
| **Mobile Carrier** | Turkcell (Turk Telekomunikasyon A.S.) |
| **Connection Type** | LTE/5G Mobile |
| **IP Classification** | Residential Mobile |
---
## Threat Profile
| Indicator | Status |
|---|---|
| **Risk Score** | 40 (Moderate) |
| **DNSBL Listings** | 2 of 8 lists |
| **Tor Exit Node** | No |
| **Known Attacker** | No |
| **Spam Source** | No |
| **Blacklist Count** | 0 active |
| **Threat Indicators** | None detected |
Observed Behavior: No open ports, no services running, firewall-protected endpoint. DNS resolves to dynamic hostname `95.10.12.162.dynamic.ttnet.com.tr`, consistent with residential/mobile broadband service.
---
## Historical Analysis
Observation Count: 19 signals
Threat Persistence: 0 days
Ownership Changes: 0
Recent signals (2026-07-30):
- Geo validation: Consistent with claimed Turkish location (RTT: 167.2ms avg)
- Network classification: Stable "clean" status
- No persistent malicious activity detected
Temporal Risk Trend: Stable. No escalation observed in recent observation window.
---
## Neighborhood Assessment
| Metric | Value |
|---|---|
| **Subnet** | 95.10.12.162/24 |
| **Abuse Density** | 0.0% (Clean) |
| **Threat Siblings** | 0 |
| **Active Siblings** | 1 |
| **High Risk Neighbors** | 0 |
Assessment: The /24 subnet is clean with no correlated abuse activity. This IP operates in isolation from malicious neighbors.
---
## Relationship Graph
Associated Entities:
- Network: TurkTelekom (6 relationship entries)
- DNS Hostname: 95.10.12.162.dynamic.ttnet.com.tr (6 entries)
No organizational or certificate relationships detected beyond ISP infrastructure.
---
## Recommended Actions
| Risk Level | Recommendation |
|---|---|
| **Low** | Standard residential/mobile IP classification |
| **Monitoring** | Track DNSBL listings if used in threat correlation |
| **Blocking** | Not recommended (no active threat indicators) |
Firewall Rules: No specific rules recommended. Default allow/deny based on organizational policy for Turkish residential IPs.
---
## Conclusion
IP 95.10.12.162 is a legitimate Turkish mobile residential endpoint with moderate risk primarily due to DNSBL presence. The subnet demonstrates clean operational characteristics with no abuse density. No immediate threat action required. Continue standard monitoring for residential mobile IP traffic patterns.
Analyst Notes: DNSBL listings may indicate historical activity or false positives. No correlation with known active campaigns. Subnet-level threat indicators are absent.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | AS9121-MNT |
| ASN | AS9121 |
| Network Name | TurkTelekom |
| CIDR Block | 95.10.0.0/16 |
| RIR | RIPE |
| Country | tr |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 95.10.12.162.dynamic.ttnet.com.tr |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 95.10.12.162.dynamic.ttnet.com.tr |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 8% | 2 | 2 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-27 15:47:12 UTC |
| Last Seen | 2026-07-30 13:48:13 UTC |
| Profile Built | 2026-07-30 13:58:09 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 20 |
Full dossier details are available via our API.