IP INTELLIGENCE BRIEFING: 139.162.149.220
Classification: LOW RISK / Cloud Infrastructure
Date: 2026-08-12
Executive Summary:
IP 139.162.149.220 is a Linode cloud compute resource located in Frankfurt am Main, Germany (AS63949). The IP presents a low-risk profile with a risk score of 25/100. Analysis indicates legitimate hosting infrastructure with no active threat indicators or persistent malicious behavior.
Ownership & Infrastructure:
- Provider: Linode (AS63949)
- Network: 139.162.0.0/16 (EU-LINODE-20141229)
- Location: Frankfurt am Main, Hesse, Germany
- Infrastructure Type: Cloud Compute
- Ownership Stability: Stable with zero ownership changes observed
Network Services:
- Port 80/tcp: HTTP (nginx/1.24.0 Ubuntu)
- Port 443/tcp: HTTPS
- Port 22/tcp: SSH (OpenSSH 9.6p1 Ubuntu-3ubuntu13.18)
- TLS Certificate: Let's Encrypt issued for hr-home.objects.ws
- DNS Resolution: 139-162-149-220.ip.linodeusercontent.com
Threat Assessment:
- Risk Score: 25 (Low Risk)
- Threat Indicators: None observed
- Known Attacker: False
- Tor Exit Node: False
- Blacklist Status: Listed on 1 of 8 DNSBLs (minor reputation impact)
- Abuse Confidence: Not elevated
- Threat Persistence: Zero days (not persistently malicious)
Historical Analysis:
28 signal observations recorded. Recent observations confirm:
- Valid SPF and DMARC records present for associated domains (objects.ws, linodeusercontent.com)
- Geographic validation consistent with Frankfurt location (avg RTT: 112.8ms, distance: 296.5km)
- No escalation in threat profile over observation period
Neighborhood Analysis:
- Subnet: 139.162.149.220/24
- Abuse Density: 0 (low)
- Risk Distribution: No high-risk neighbors identified
- Classification: Mostly clean subnet
Recommendations:
- Action: Monitor as standard cloud infrastructure; no immediate blocking required
- Firewall: Allow inbound traffic on ports 80, 443, 22 if business requires SSH access
- Monitoring: Continue baseline monitoring for any changes in threat profile
- Context: IP is part of legitimate Linode hosting infrastructure with proper email authentication configured
Conclusion:
This IP represents routine cloud hosting activity from a major provider. The low-risk score, proper DNS/email authentication, and lack of threat indicators support classifying this as benign infrastructure requiring standard monitoring.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | linode-mnt |
| ASN | AS63949 |
| Network Name | EU-LINODE-20141229 |
| CIDR Block | 139.162.0.0/16 |
| RIR | ARIN |
| Country | US |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 139-162-149-220.ip.linodeusercontent.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | 139-162-149-220.ip.linodeusercontent.com |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | 1/2 domains |
| DMARC | 1/2 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
| Domains Checked | 2 domains |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | nginx/1.24.0 (Ubuntu) |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18 |
๐ TLS Certificate
| SANs | hr-home.objects.ws |
| Valid From | 2026-07-13T14:35:55+00:00 |
| Valid Until | 2026-10-11T14:35:54+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
| Serial Number | 05706BEB7A7A3AE85EA474A895E9BB76F007 |
| Thumbprint | 585186C4B9DA40C62D365F1BB16933781EEDB7F7 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 43% | 2 | 5 |
| routing | 13% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 30% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 30% | 10 | 18 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-22 13:23:38 UTC |
| Last Seen | 2026-08-12 16:48:38 UTC |
| Profile Built | 2026-08-12 16:56:42 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 27 |
Full dossier details are available via our API.