IPDebrief

104.168.159.150

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# Intelligence Briefing: 104.168.159.150

## Executive Summary

IP 104.168.159.150 is a low-risk hosting infrastructure address operated by Hostwinds (ASN 54290). The IP resolves to a web hosting environment serving geturbooking.com with standard web services and no active threat indicators.

## Profile Overview

## Technical Details

## DNS and Security Configuration

## Threat Assessment

## Historical Analysis

Analysis of 22 observations indicates stable operational patterns:

## Relationship Graph

The IP maintains associations with:

## Subnet Neighborhood Analysis

## Recommended Actions

Based on risk score of 25 and absence of active threat indicators, no immediate blocking or mitigation actions are recommended. The IP represents a standard commercial hosting environment with expected security controls in place.

## Intelligence Narrative

The target IP 104.168.159.150 operates as a commercial web hosting service within a colocation infrastructure environment. DNS records confirm association with the geturbooking.com domain, serviced through Hostwinds hosting. The IP exhibits standard web server behavior with nginx serving HTTP/HTTPS traffic and SSH access configured. No malicious activity, known attacker patterns, or campaign correlations were identified in the observation history. The subnet demonstrates low abuse density with minimal threat sibling presence. While one DNSBL listing exists, it does not correlate with active threat indicators. The infrastructure maintains stable operational characteristics with no evidence of malicious repurposing.

Risk Level: LOW

Recommended Handling: Monitor as standard infrastructure

Priority: LOW

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
Regionβ€”
Cityβ€”
Timezoneβ€”
Latitude37.75
Longitude-97.82

🏒 Ownership & Registration

OrganizationHostPapa
ASNAS54290
Network Nameβ€”
CIDR Blockβ€”
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRhwsrv-1327114.hostwindsdns.com
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnameshwsrv-1327114.hostwindsdns.com

πŸ” DNS Hygiene

Hygiene Score40% (Fair)
SPF0/2 domains
DMARC0/2 domains
FCrDNSVerified
DNSSECValid
CAANot configured
Domains Checked2 domains

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeWeb Server
Network TierHosting β€” Infrastructure provider without advanced routing
Hosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpβ€”
443httpstcpβ€”
22sshtcp
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
Servernginx/1.24.0 (Ubuntu)
HTTP Titleβ€”
SSH VersionSSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16

πŸ” TLS Certificate

πŸ”’
CN=geturbooking.com
Issued by CN=YE2, O=Let's Encrypt, C=US
Self-signed: No
SANsgeturbooking.comwww.geturbooking.com
Valid From2026-06-06T21:33:53+00:00
Valid Until2026-09-04T21:33:52+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha384ECDSA
Validity Period89 days
Serial Number05B67908F96C8873EABB95CA3702AECA26EC
Thumbprint472ED20AE16A97BB40E94AA0DCB46F8948EE8301

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
29%
24
routing
8%
11
services
30%
23
ownership
24%
23
reputation
26%
13
geolocation
19%
22
Overall23%1016
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-15 08:42:42 UTC
Last Seen2026-06-28 01:57:15 UTC
Profile Built2026-06-28 20:03:32 UTC
Data FreshnessLive
Signal Types21
Total Observations25
πŸ” 21 signal types Β· 25 observations collected
This report is generated from 21+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.