# INTELLIGENCE BRIEFING: 139.144.31.96
## EXECUTIVE SUMMARY
IP address 139.144.31.96 is a Linode cloud computing infrastructure address (ASN 63949) located in Atlanta, GA, US. The IP carries a moderate risk score of 40 and is associated with a /24 subnet exhibiting high abuse density. While the IP itself shows no active threat indicators, contextual subnet analysis suggests elevated risk from neighboring addresses.
## OWNERSHIP AND INFRASTRUCTURE
- Organization: Linode LLC
- ASN: AS63949
- Infrastructure Type: CloudCompute
- Geolocation: United States, Atlanta, GA (2500km accuracy radius)
- CIDR Block: 139.144.16.0/20 (control plane)
- Network Classification: Hosting/Cloud provider infrastructure
- Service Status: Firewalled / No Services Detected
## THREAT PROFILE
- Risk Score: 40 (Moderate Risk)
- DNSBL Listings: 1 of 8 total lists
- Known Threat Indicators: None identified
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Campaign Associations: None detected
## SUBNET CONTEXT (139.144.31.0/24)
- Abuse Density: 0.5714 (High Abuse Classification)
- Total Siblings: 7
- Active Siblings: 7
- Threat Siblings: 4
- Neighboring IPs: All 6 neighbors show consistent risk score of 40 with authority scores 50-60
## OBSERVATION HISTORY
Recent signal observations (June 2026) indicate:
- Multiple Linode infrastructure confirmations across multiple data sources
- Subnet abuse density classification of "high_abuse" recorded 06-20-2026
- Alienvault OTX signals showing threat-related activity from related addresses
- No ownership changes detected; IP has remained stable under Linode control
## RELATIONSHIP ANALYSIS
The IP demonstrates 24 relationships, all classified as "Same Network" pointing to LINODE infrastructure. This indicates the IP is part of a dense Linode hosting environment with no external organizational relationships identified.
## RECOMMENDED ACTIONS
Based on risk profile and subnet context, the following firewall rules are recommended:
Blocking Rules:
- iptables: `iptables -A INPUT -s 139.144.31.96 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 139.144.31.96 drop`
- nginx: `deny 139.144.31.96;`
- pfSense: `139.144.31.96/32`
Cloud WAF Rules:
- Cloudflare: Block with expression `ip.src eq 139.144.31.96`
- AWS WAF: Block address `139.144.31.96/32`
## SOC ANALYST NOTES
The IP does not show active malicious indicators but operates within a subnet with high abuse density (0.5714) where 4 of 7 neighboring IPs are classified as threats. The moderate risk score of 40 combined with subnet context suggests this address may be used for compromised cloud infrastructure or as part of broader abuse campaigns. Monitoring of the entire 139.144.31.0/24 subnet is recommended. No immediate threat activity observed on this specific IP, but subnet-level blocking may be warranted based on neighborhood analysis.
Confidence Level: Moderate
Last Updated: 2026-06-28
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Linode |
| ASN | AS63949 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 31% | 2 | 3 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-17 03:07:24 UTC |
| Last Seen | 2026-06-28 04:10:52 UTC |
| Profile Built | 2026-06-29 04:15:50 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 25 |
Full dossier details are available via our API.