INTELLIGENCE BRIEFING: 152.32.169.169/32
Classification: LOW RISK โ Passive Infrastructure
Executive Summary
IP address 152.32.169.169 is classified as low-risk with no active threat indicators. The IP exhibits passive behavior with no open services or public-facing applications. Geolocation data shows US-NY (New York) consensus, though historical observations include Hong Kong geolocation data. The IP maintains a 0/100 risk score across all dimensions.
---
1. PROFILE ASSESSMENT
| Attribute | Value |
|---|---|
| Risk Score | 0/100 |
| Provider Score | 0/100 |
| Authority Score | 0/100 |
| Reputation | Low Risk |
| ASN/Ownership | Not Available |
| Network Role | Firewall / No Services |
Network Characteristics:
- Services: No open ports detected
- DNS: No PTR records, no forward resolution, no hosted domains
- Email Auth: No SPF/DMARC records (no domain associated)
- Tor/Proxy: Not a Tor exit node, not a known proxy
- Cloud/CDN: No CDN or cloud infrastructure detected
---
2. THREAT INDICATORS
| Indicator | Status |
|---|---|
| Blacklist Count | 0 |
| Known Campaign | None |
| Threat Feeds | None |
| Honeypot Hits | 0 |
| Enumeration Strikes | 0 |
| WAF Violations | 0 |
| DNSBL Listings | 0 |
| Is Known Attacker | False |
| Is Spam Source | False |
Assessment: No malicious activity detected. IP is not associated with any threat feeds, campaigns, or abuse databases.
---
3. GEOLOCATION ANALYSIS
Current Consensus: New York, US (US-NY)
- Accuracy: Confirmed by single source
- Timezone: America/New_York
Historical Observations (Last 10):
- 2026-07-29: Hong Kong (confidence 0.70, source: MaxMind GeoLite2)
- Geographic inconsistency noted between current profile and historical data
Assessment: Geolocation data shows minor inconsistencies typical of residential/ISP addresses. No malicious geolocation manipulation detected.
---
4. NETWORK BEHAVIOR
| Metric | Value |
|---|---|
| Traceroute Hops | 24 |
| Transit Network | Comcast |
| Timed Out Hops | 11 |
| First Hop RTT | 0.2ms |
| Last Hop RTT | 230.4ms |
| SSH Banner | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13 |
| Port Scan Activity | Detected |
Behavioral Indicators:
- No persistent malicious behavior
- No auto-banned status
- No active attacker classification
- Threat persistence days: 0
---
5. NEIGHBORHOOD ANALYSIS (152.32.169.0/24)
Subnet Assessment:
- Abuse Density: 0 (no abuse detected)
- Total Siblings: 2
- Risk Distribution: 1 medium, 1 low, 0 high
Notable Neighbors:
| IP Address | Risk Score | Authority Score |
|---|---|---|
| 152.32.169.42 | 40 | 50 |
| 152.32.169.153 | 25 | 50 |
Assessment: Subnet shows minimal abuse activity. Neighbor 152.32.169.42 exhibits moderate risk (40/100) while 152.32.169.153 remains low risk (25/100).
---
6. RELATIONSHIP GRAPH
Status: No relationships detected (0 links)
Associated Entities: None
Certificates: None
---
7. SECURITY ACTIONS RECOMMENDATION
Recommendation: MONITOR โ No immediate action required
Justification:
- Risk score: 0/100
- No active threat indicators
- Passive infrastructure with no open services
- No firewall rules recommended
Monitoring Priority: LOW
---
8. OBSERVATION HISTORY
Total Observations: 10
Most Recent: 2026-07-29
Key Historical Signals:
- SSH service detected (OpenSSH 9.6p1 on Ubuntu)
- Port scanning activity observed
- Multiple blacklist checks performed (8 total listings, 0 listed)
- DNSSEC evaluation: Minimal rating
Temporal Analysis:
- Ownership changes: 0
- Threat observation count: 0
- Persistently malicious: False
---
INTELLIGENCE CONCLUSION
IP 152.32.169.169 represents passive network infrastructure with no malicious activity detected. The IP is firewall-protected with no public-facing services. Historical observations show minor geolocation inconsistencies but no evidence of malicious manipulation. The surrounding subnet (152.32.169.0/24) exhibits minimal abuse activity.
Recommended Action: Standard monitoring protocols. No blocking or filtering recommended at this time.
---
*Intelligence generated by IPDebrief threat analysis system. Data collected as of 2026-07-29.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | UCLOUD INFORMATION TECHNOLOGY HK LIMITED |
| ASN | AS135377 |
| Network Name | UCLOUD-HK |
| CIDR Block | 152.32.169.0/24 |
| RIR | ARIN |
| Country | HK |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 35% | 2 | 2 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 14% | 4 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-21 06:46:46 UTC |
| Last Seen | 2026-07-29 07:03:22 UTC |
| Profile Built | 2026-07-29 07:12:59 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 20 |
Full dossier details are available via our API.