IPDebrief

139.162.55.218

IP Intelligence Dossier
Your IP: 216.73.217.135
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING

Target: 139.162.55.218/32

Classification: Low Risk Cloud Compute Infrastructure

Date: 2026-06-26

## EXECUTIVE SUMMARY

IP 139.162.55.218 is a Linode cloud compute instance (ASN 63949) hosted in Singapore. The IP demonstrates low-risk characteristics with a risk score of 25. While the IP itself shows no direct malicious indicators, it is associated with a DNS blacklist and exists within a subnet exhibiting elevated threat sibling activity.

## INFRASTRUCTURE PROFILE

## NETWORK SERVICES

## THREAT ASSESSMENT

Direct Indicators: None detected

Control Plane Signals:

## NEIGHBORHOOD ANALYSIS (139.162.55.0/24)

- 139.162.55.244: Risk Score 25, Authority Score 60

The subnet exhibits mixed risk characteristics. The target IP is classified as low-risk within a subnet containing 2 threat siblings, suggesting potential infrastructure sharing with lower-risk entities.

## OBSERVATION HISTORY

Total Signals Observed: 23

Recent Notable Signals (2026-06-26):

Temporal Indicators:

## RELATIONSHIP MAPPING

Primary Relationships (63 total):

The IP is linked to the Linode EU network and associated with the Vietnamese domain iconnect.vn.

## RECOMMENDED ACTIONS

Current Risk Level: Low

Recommended Status: Monitor

---

Analyst Notes: This IP represents standard cloud infrastructure hosting web services. The 403 Forbidden response and DNSBL association warrant continued monitoring but do not indicate active exploitation. The geographic discrepancy between Singapore profile and US inference in recent signals may indicate multi-region CDN routing or data inconsistency.

Intelligence Confidence: High (based on comprehensive profile and relationship data)

Action Priority: Medium (monitor subnet threat siblings)

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΈπŸ‡¬ Singapore
Regionβ€”
CitySingapore
Timezoneβ€”
Latitude1.29
Longitude103.85

🏒 Ownership & Registration

Organizationlinode-mnt
ASNAS63949
Network Nameβ€”
CIDR Blockβ€”
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRapp.iconnect.vn
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamesapp.iconnect.vn

πŸ” DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeWeb Server
Network TierHosting β€” Infrastructure provider without advanced routing
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpβ€”
443httpstcpβ€”
22sshtcp
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
ServerApache/2.2.15 (CentOS)
HTTP Titleβ€”
SSH VersionSSH-2.0-OpenSSH_5.3

πŸ” TLS Certificate

An expired certificate for E=root@srv55.iconnect.vn, CN=srv55.iconnect.vn, OU=SomeOrganizationalUnit, O=SomeOrganization, L=SomeCity, S=SomeState, C=-- was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.
⚠️
E=root@srv55.iconnect.vn, CN=srv55.iconnect.vn, OU=SomeOrganizationalUnit, O=SomeOrganization, L=SomeCity, S=SomeState, C=--
Issued by E=root@srv55.iconnect.vn, CN=srv55.iconnect.vn, OU=SomeOrganizationalUnit, O=SomeOrganization, L=SomeCity, S=SomeState, C=--
Self-signed: Yes
SANsNone
Valid From2019-09-06T04:17:37+00:00
Valid Until2020-09-05T04:17:37+00:00 (expired)
TLS ProtocolTls12
Cipher SuiteTLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period365 days
Serial Number0EC5
ThumbprintC94D1A00E515B7935155894DC72C97458A62BD78

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
32%
24
routing
13%
11
services
28%
23
ownership
20%
23
reputation
28%
13
geolocation
37%
23
Overall26%1017
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceMixed Signals (68%) β€” 2 contradiction(s)
AttributionModerate (55%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Geo sources disagree on country: US, --
⚠ TLS certificate claims -- but primary geo says SG

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-10 10:13:09 UTC
Last Seen2026-06-27 17:19:06 UTC
Profile Built2026-06-28 11:24:27 UTC
Data FreshnessLive
Signal Types23
Total Observations27
πŸ” 23 signal types Β· 27 observations collected
This report is generated from 23+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.