# IP Intelligence Briefing: 104.64.221.171
## Executive Summary
IP address 104.64.221.171 is a Linode cloud compute infrastructure endpoint with a moderate risk score of 50. The IP is located in Singapore and is associated with the 104.64.192.0/19 BGP prefix (ASN 63949). No active threat indicators, campaigns, or malicious behavior were detected. The IP appears to be a legitimate cloud-hosted service endpoint.
## Technical Profile
Classification: Cloud compute infrastructure (Linode)
Country: Singapore (SG)
ASN: 63949
BGP Prefix: 104.64.192.0/19
DNS Hostname: 104-64-221-171.ip.linodeusercontent.com
PTR Resolution: Forward confirmed
Services: No open ports detected (firewalled/no services)
DNSBL Status: Listed on 2 of 8 threat lists
## Risk Assessment
- Overall Risk Score: 50 (Moderate Risk)
- Abuse Confidence: Not scored
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Persistently Malicious: No
## Neighborhood Analysis
The /24 subnet (104.64.221.0/24) shows low abuse density with only 1 active sibling IP identified:
- 104.64.221.249 (Risk Score: 25, Authority Score: 60)
- No high or medium-risk neighbors detected in the immediate vicinity
## Relationship Graph
- DNS Associations: 104-64-221-171.ip.linodeusercontent.com
- No additional organizational, certificate, or hostname relationships identified beyond DNS PTR records
## Historical Observations
14 signal observations recorded over the monitoring period. Recent signals include:
- Ownership and RIR registration data (ARIN)
- Operator scoring with basic classification
- No persistent malicious activity patterns detected
- Geographic consensus confirmed
## Security Recommendations
Based on the risk profile, the following firewall rules are available for deployment:
iptables:
```bash
iptables -A INPUT -s 104.64.221.171 -j DROP
```
nftables:
```bash
nft add rule inet filter input ip saddr 104.64.221.171 drop
```
Cloudflare WAF:
```json
{
"description": "Block 104.64.221.171 β IPDebrief risk score 50",
"action": "block",
"filter": {
"expression": "ip.src eq 104.64.221.171"
}
}
```
AWS WAF:
```json
{
"Addresses": ["104.64.221.171/32"],
"Description": "IPDebrief risk 50"
}
```
## Intelligence Notes
The moderate risk score (50) correlates with DNSBL listings on 2 of 8 threat feeds, suggesting prior abuse reporting but no current malicious activity. The IP is hosted on Linode cloud infrastructure in Singapore with no open services detected, indicating it may be a backend service or firewalled endpoint. The low neighborhood abuse density and absence of threat indicators support a cautious monitoring approach rather than immediate blocking.
Recommendation: Monitor for behavioral changes or additional threat indicators. Current profile does not warrant immediate blocking, but consider geo-blocking or rate-limiting based on organizational policy for Singapore-origin traffic.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Akamai Technologies, Inc. |
| ASN | AS63949 |
| Network Name | AKAMAI-COMPUTE |
| CIDR Block | 104.64.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 104-64-221-171.ip.linodeusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 104-64-221-171.ip.linodeusercontent.com |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Multi-Service Host |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| 8080 | http-alt | tcp | β |
| Closed Ports | 25, 80, 443, 3389, 8443 (2 open / 7 scanned) | ||
| Server | fasthttp |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_10.0p2 Debian-7+deb13u4 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 21% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 13% | 1 | 1 |
| Overall | 21% | 9 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-30 17:11:00 UTC |
| Last Seen | 2026-08-13 00:45:30 UTC |
| Profile Built | 2026-08-13 00:55:10 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 24 |
Full dossier details are available via our API.