IP Intelligence Briefing: 104.164.173.60
Date: 2026-06-17
---
**1. Risk Profile**
- Risk Score: 25 (Low Risk)
- Provider: EGIHosting (ASN 18779)
- Geolocation: Santa Clara, CA, US
- Network Role: Firewalled / No Services (no open ports or active services detected)
---
**2. Threat Indicators**
- Malicious Activity: No known threats, spam, or attacker indicators.
- DNSBL Listings: 1 out of 8 DNSBL lists (low priority).
- Subnet Abuse Density: 44.44% (moderate risk within /24 subnet).
---
**3. Network Context**
- Subnet: 104.164.173.0/24
- Neighbors (8 total): All have risk scores of 25 (low risk), with 4 classified as "threat siblings."
- Ownership: Same ASN (18779) across all neighbors.
- Routing: DNSSEC validated, but BGP route stability is low (route changes in past 30 days).
---
**4. Historical Observations**
- Recent Activity:
- DNSSEC validation and subnet abuse density recorded on 2026-06-17.
- No persistent malicious activity detected.
- Long-Term Trends: No ownership or threat persistence over time.
---
**5. Relationships**
- Linked Entities:
- Subnet: EGNL-1 (same network segment).
- No direct links to organizations, domains, or certificates.
---
**6. Recommended Actions**
- Monitor Subnet: Due to 44.44% abuse density, monitor neighbors for emerging threats.
- Verify DNSBL: Investigate why this IP is listed on 1 DNSBL (potential spam or abuse).
- Check Route Stability: Review BGP route changes for potential network instability.
- No Firewall Rules: No immediate mitigation required based on current risk profile.
---
Conclusion:
104.164.173.60 is a low-risk IP associated with a mixed-risk subnet. While no direct threats are detected, the subnetβs abuse density and DNSBL listing warrant ongoing monitoring. No immediate action is required, but contextualize this IP within its network segment for broader threat assessment.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | EGIHosting |
| ASN | AS18779 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 47% | 2 | 5 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:03:27 UTC |
| Last Seen | 2026-06-22 07:39:37 UTC |
| Profile Built | 2026-06-22 07:44:28 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 20 |
Full dossier details are available via our API.