Threat Intelligence Briefing: IP 142.111.152.9/32
Date: 2026-06-17
Overview:
- Risk Profile: Moderate risk (score: 40) with no direct malicious indicators.
- Ownership: Registered to Ace Data Centers II, L.L.C. (ASN 212238) in Houston, TX, US.
- Geolocation: Plausible US location with 2,500 km accuracy radius.
- Network Role: Firewalled infrastructure with no open ports or active services detected.
- Subnet Context: Part of 142.111.152.0/24, classified as "high_abuse" with 24/37 sibling IPs flagged as threats.
Key Findings:
1. Subnet Risk: The subnet exhibits high abuse density (0.6486), with 24 malicious neighbors and 16 active IPs.
2. Network Configuration: Securely configured with no exposed services, but linked to a high-risk subnet.
3. Threat Indicators: No direct malicious activity (no blacklists, spam, or campaigns).
4. BGP Context: Route stability is questionable (route changes in 30 days: 0, but "is_route_stable": false).
Actionable Recommendations:
- Monitor Subnet: Given the high abuse density, investigate potential lateral movement or compromised hosts within the 142.111.152.0/24 subnet.
- Block Subnet: Consider blocking the entire subnet in firewalls (e.g., iptables, nftables) due to the elevated risk profile.
- Verify Ownership: Confirm Ace Data Centers II, L.L.C. is a legitimate provider to rule out spoofing.
- Check for Enumeration: Monitor for DNS or network enumeration attempts targeting this subnet.
Next Steps:
- Cross-reference with internal threat feeds for any missed indicators.
- Validate BGP route stability and RPKI compliance for the 142.111.152.0/24 prefix.
- Correlate with other IPs in the subnet (e.g., 142.111.152.1, 142.111.152.3) for potential clusters.
Note: While the IP itself is clean, its association with a high-risk subnet warrants further investigation to mitigate potential indirect threats.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Ace Data Centers II, L.L.C. |
| ASN | AS212238 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 21% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:03:42 UTC |
| Last Seen | 2026-06-22 15:08:00 UTC |
| Profile Built | 2026-06-22 15:17:55 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 20 |
Full dossier details are available via our API.