## IP Intelligence Briefing: 154.16.119.22/32
Classification: Moderate Risk (Risk Score: 50)
Analysis Date: Current
Prepared For: SOC Analyst Review
---
OWNERSHIP & INFRASTRUCTURE
The IP address 154.16.119.22 is allocated to HostforWeb Support (ASN 14670) under the RIR afrinic. The network block is 154.16.116.0/22 (154.16.116.0 - 154.16.119.255). The IP is classified as a hosted infrastructure resource with the service purpose noted as "Firewalled / No Services." No open ports were detected across the monitored services.
Geolocation: The IP resolves to coordinates 52.13, 5.29 in the Netherlands (NL) with a 225km accuracy radius. Timezone is Europe/Amsterdam. Geo consensus is reported as true with one geo source.
NETWORK CLASSIFICATION & SERVICES
The IP is not classified as a provider, CDN, VPN, proxy, Tor exit node, hosting service, mobile carrier, residential, bogon, or anycast network. DNS PTR records resolve to "pitchmystuff.com" with one forward hostname confirmed. No email authentication records (SPF, DMARC) were detected for the associated domain. No TLS certificates or HTTP titles were observed.
THREAT INDICATORS
- Blacklist Status: Listed on 2 out of 8 DNSBLs
- Known Campaigns: None detected
- Threat Feeds: Empty
- Abuse Confidence Score: Not available
- Tor/Proxy/Spam Status: False
- Known Attacker Status: False
- Campaign Likelihood: None detected
OBSERVATION HISTORY
Sixteen total observations recorded. Recent activity (2026-06-25) shows operator scores at minimal levels. Historical data indicates blacklist listings with high severity on multiple feeds. Geolocation signals consistently infer Netherlands placement. The IP demonstrates threat persistence of 0 days and is not marked as persistently malicious.
RELATIONSHIP ANALYSIS
Twenty-six relationships identified:
- Network: Multiple same-network associations to 154.16.116.0 - 154.16.119.255
- DNS: Multiple hostname associations to pitchmystuff.com
- Organizations/Certificates: None detected
NEIGHBORHOOD ASSESSMENT
Subnet 154.16.119.22/24 analysis:
- Abuse Density: 0 (Low)
- Classification: Mostly clean
- Inherited Risk: 2
- Total Siblings: 1
- Active Siblings: 0
- Threat Siblings: 1
- No additional neighboring IPs with available data.
CONTROL PLANE DATA
- Origin ASN: 14670
- BGP Prefix: 154.16.119.0/24
- Route Stability: False
- RPKI State: Not available
- IRR Consistency: Not available
- Route Changes (30d): 0
- DNSSEC Valid: True
- Operator Score: 0.1304 (Minimal)
RECOMMENDED ACTIONS
Based on risk score 50, the following defensive rules are recommended:
iptables:
```
iptables -A INPUT -s 154.16.119.22 -j DROP
```
nftables:
```
nft add rule inet filter input ip saddr 154.16.119.22 drop
```
nginx:
```
deny 154.16.119.22;
```
pfSense:
```
154.16.119.22/32
```
Cloudflare WAF: Block IP 154.16.119.22 (risk score 50)
AWS WAF:
```
Addresses: ["154.16.119.22/32"]
Description: IPDebrief risk 50
```
---
Assessment Summary: The IP presents moderate risk with a score of 50. While not a known malicious actor, it appears on multiple DNSBLs (2/8 lists) and has historical blacklist associations with high severity ratings. The lack of open services and firewalled status suggests limited direct exposure. The DNS association with pitchmystuff.com warrants monitoring for potential command-and-control activity. Block recommendation is advised pending correlation with internal threat indicators.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | HostforWeb Support |
| ASN | AS14670 |
| Network Name | 154.16.116.0 - 154.16.119.255 |
| CIDR Block | 154.16.116.0/22 |
| RIR | AFRINIC |
| Country | NL |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | pitchmystuff.com |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | pitchmystuff.com |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 19% | 2 | 2 |
| reputation | 26% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 20% | 9 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Fresh
| First Seen | 2026-05-08 11:09:56 UTC |
| Last Seen | 2026-06-26 18:10:41 UTC |
| Profile Built | 2026-06-26 00:24:56 UTC |
| Data Freshness | Fresh |
| Signal Types | 17 |
| Total Observations | 18 |
Full dossier details are available via our API.