IPDebrief

149.102.144.215

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 149.102.144.215/32

Date: Current

Classification: Low Risk

Analyst: IPDebrief Intelligence Team

## Executive Summary

IP 149.102.144.215 presents as a low-risk web server infrastructure endpoint with minimal threat indicators. The IP operates as a Contabo-hosted web server within the Cogent Communications network infrastructure. While the endpoint itself shows low risk, the /24 subnet contains one threat-identified sibling IP, warranting monitoring of related addresses.

## Ownership and Infrastructure

## Network Services

The endpoint exposes three open ports:

Web Server Stack:

## DNS Analysis

## Threat Indicators

Control Plane Indicators:

## Neighborhood Analysis

One adjacent IP in the /24 subnet has been flagged for threat activity.

## Relationship Graph

The IP maintains 45 recorded relationships, primarily:

## Observation History

## Security Recommendations

Immediate Actions:

1. Monitor Sibling IPs: The /24 subnet contains one threat-identified sibling IP. Add 149.102.144.0/24 to monitoring watchlist.

2. DNS Security Gap: Verify SPF and DMARC records for co.ke domain.

3. SSH Exposure: Port 22 is open. Confirm this is intentional and consider restricting access.

Firewall Rules (Recommended):

```bash

# Block if SSH should not be accessible

iptables -A INPUT -p tcp --dport 22 -j DROP

# Allow HTTP/HTTPS with rate limiting

iptables -A INPUT -p tcp --dport 80 -m limit --limit 10/min -j ACCEPT

iptables -A INPUT -p tcp --dport 443 -m limit --limit 10/min -j ACCEPT

```

Monitoring Priority: LOW

The endpoint itself does not require immediate blocking. Focus monitoring efforts on the sibling threat IP within the same subnet.

---

Data Sources: IPDebrief Intelligence Platform

Confidence Level: Moderate

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionEngland
CityPortsmouth
Timezoneβ€”
Latitude50.85
Longitude-0.99

🏒 Ownership & Registration

OrganizationCogent Communications, LLC
ASNAS51167
Network Nameβ€”
CIDR Blockβ€”
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRlipanet.co.ke
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnameslipanet.co.ke

πŸ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeWeb Server
Network TierTier 3 β€” Basic operator with some routing infrastructure
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpβ€”
443httpstcpβ€”
22sshtcp
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
ServerTengine
HTTP Titleβ€”
SSH VersionSSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16

πŸ” TLS Certificate

An expired certificate for CN=hotspot.lipanet.co.ke was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.
πŸ”’
CN=hotspot.lipanet.co.ke
Issued by CN=R12, O=Let's Encrypt, C=US
Self-signed: No
SANshotspot.lipanet.co.ke
Valid From2026-03-22T20:35:00+00:00
Valid Until2026-06-20T20:34:59+00:00 (expired)
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period89 days
Serial Number06FB5CC3AFCD62EEAA1573D07870DA8F6059
ThumbprintF49E2F5548DD8493C7E96F60E3EC1760712543A9

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
24
routing
13%
11
services
26%
23
ownership
24%
23
reputation
26%
13
geolocation
33%
23
Overall24%1017
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-21 14:56:15 UTC
Last Seen2026-06-28 13:41:09 UTC
Profile Built2026-06-29 01:43:48 UTC
Data FreshnessLive
Signal Types23
Total Observations26
πŸ” 23 signal types Β· 26 observations collected
This report is generated from 23+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.