# IP Intelligence Briefing: 144.225.6.161/32
## Executive Summary
IP 144.225.6.161 presents a Moderate Risk (Score: 50) classification with no active threat indicators. The address is classified as "Firewalled / No Services" with zero open ports, suggesting defensive posture. Geographic validation anomalies detected but no persistent malicious activity observed.
---
## Network Ownership & Classification
- ASN: 7488 (Private Customer)
- Network: NET-144-225-6-0-24/24
- RIR: ARIN
- Country: United States
- Infrastructure Type: Firewalled / No Services
- Classification Flags: Not Cloud/CDN/VPN/Proxy/Tor/Hosting/Mobile/Residential
---
## Threat Intelligence Assessment
| Indicator | Status |
|---|---|
| Threat Indicators | None |
| Tor Exit Node | No |
| Known Attacker | No |
| Spam Source | No |
| Blacklist Count | 0 |
| DNSBL Listed | 2 of 8 lists |
| Known Campaigns | None |
| Abuse Confidence Score | Not Assigned |
Risk Breakdown: Risk Score 50/100 with provider/authority scores at 0. No evidence of active exploitation or campaign association.
---
## Network Behavior & Services
- Open Ports: None detected
- TLS Certificate: None
- HTTP Banner: None
- Email Authentication: SPF/DMARC not configured
- DNS Resolution: Forward resolution failed; no PTR records
---
## Geographic & Network Routing
- Claimed Location: United States (confidence 0.35)
- Geographic Validation: ⚠️ Anomaly detected — 7,626km distance from RTT measurements inconsistent (113ms < 152.5ms minimum)
- Traceroute: 14 hops via Comcast and GTT networks
- Route Stability: Unstable (isRouteStable: false)
- DNSSEC: Valid
---
## /24 Neighborhood Analysis
- Abuse Density: 0.25 (mostly_clean)
- Total Siblings: 4
- Active Siblings: 2
- Threat Siblings: 1
- Risk Distribution: 0 high / 1 medium / 2 low risk
Notable Neighbors:
- 144.225.6.82: Risk 0 (Low)
- 144.225.6.182: Risk 50 (Medium)
- 144.225.6.221: Risk 25 (Low)
---
## Historical Observations
- Total Signals: 17 observations
- Last Observed: 2026-07-28
- Threat Persistence: 0 days
- Ownership Changes: 0
Recent observations include TLS/SSH signatures, geolocation probes, and subnet classification. No escalation in threat profile detected.
---
## Recommended Actions
Current Risk Level: Moderate — Monitor but no immediate blocking required
Suggested Firewall Rules:
- Allow passive traffic only (no services exposed)
- Monitor DNSBL activity (2 of 8 lists)
- Continue geo-validation monitoring
Priority: LOW — IP shows defensive characteristics with no active malicious indicators. The moderate risk score reflects DNSBL listings and geographic validation anomalies rather than confirmed threat activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Private Customer |
| ASN | AS7488 |
| Network Name | NET-144-225-6-0-24 |
| CIDR Block | 144.225.6.0/24 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 0% (None) |
| SPF | 0/2 domains |
| DMARC | 0/2 domains |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
| Domains Checked | 2 domains |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Multi-Service Host |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | Banner detected |
| 8443 | https-alt | tcp | — |
| Closed Ports | 25, 80, 443, 3389, 8080 (2 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | smalllinkfj20260709.duckdns.org |
| Valid From | 2026-07-09T03:08:04+00:00 |
| Valid Until | 2026-10-07T03:08:03+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256RSA |
| Validity Period | 89 days |
🛡️ Public Network Snapshot
| Origin ASN | AS7488 |
| Network Prefix | 144.225.6.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 5 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 12% | 2 | 2 |
| reputation | 16% | 1 | 4 |
| geolocation | 20% | 2 | 4 |
| Overall | 15% | 10 | 18 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-19 05:58:19 UTC |
| Last Seen | 2026-09-29 03:06:20 UTC |
| Profile Built | 2026-09-28 14:56:06 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 27 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 144.225.6.161
Who owns the IP address 144.225.6.161?
144.225.6.161 is registered to Private Customer. The address falls within the 144.225.6.0/24 network block. Registration is held at ARIN.
Where is 144.225.6.161 located?
Geolocation data places 144.225.6.161 in Los Angeles, CA, United States. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 144.225.6.161 malicious or safe?
144.225.6.161 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 144.225.6.161?
Responsive ports observed on 144.225.6.161 include 22, 8443. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.