IPDebrief

154.16.119.22

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

## IP Intelligence Briefing: 154.16.119.22/32

Classification: Moderate Risk (Risk Score: 50)

Analysis Date: Current

Prepared For: SOC Analyst Review

---

OWNERSHIP & INFRASTRUCTURE

The IP address 154.16.119.22 is allocated to HostforWeb Support (ASN 14670) under the RIR afrinic. The network block is 154.16.116.0/22 (154.16.116.0 - 154.16.119.255). The IP is classified as a hosted infrastructure resource with the service purpose noted as "Firewalled / No Services." No open ports were detected across the monitored services.

Geolocation: The IP resolves to coordinates 52.13, 5.29 in the Netherlands (NL) with a 225km accuracy radius. Timezone is Europe/Amsterdam. Geo consensus is reported as true with one geo source.

NETWORK CLASSIFICATION & SERVICES

The IP is not classified as a provider, CDN, VPN, proxy, Tor exit node, hosting service, mobile carrier, residential, bogon, or anycast network. DNS PTR records resolve to "pitchmystuff.com" with one forward hostname confirmed. No email authentication records (SPF, DMARC) were detected for the associated domain. No TLS certificates or HTTP titles were observed.

THREAT INDICATORS

OBSERVATION HISTORY

Sixteen total observations recorded. Recent activity (2026-06-25) shows operator scores at minimal levels. Historical data indicates blacklist listings with high severity on multiple feeds. Geolocation signals consistently infer Netherlands placement. The IP demonstrates threat persistence of 0 days and is not marked as persistently malicious.

RELATIONSHIP ANALYSIS

Twenty-six relationships identified:

NEIGHBORHOOD ASSESSMENT

Subnet 154.16.119.22/24 analysis:

CONTROL PLANE DATA

RECOMMENDED ACTIONS

Based on risk score 50, the following defensive rules are recommended:

iptables:

```

iptables -A INPUT -s 154.16.119.22 -j DROP

```

nftables:

```

nft add rule inet filter input ip saddr 154.16.119.22 drop

```

nginx:

```

deny 154.16.119.22;

```

pfSense:

```

154.16.119.22/32

```

Cloudflare WAF: Block IP 154.16.119.22 (risk score 50)

AWS WAF:

```

Addresses: ["154.16.119.22/32"]

Description: IPDebrief risk 50

```

---

Assessment Summary: The IP presents moderate risk with a score of 50. While not a known malicious actor, it appears on multiple DNSBLs (2/8 lists) and has historical blacklist associations with high severity ratings. The lack of open services and firewalled status suggests limited direct exposure. The DNS association with pitchmystuff.com warrants monitoring for potential command-and-control activity. Block recommendation is advised pending correlation with internal threat indicators.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ณ๐Ÿ‡ฑ Netherlands
RegionNew York
CityBuffalo
TimezoneEurope/Amsterdam
Latitude52.13
Longitude5.29

๐Ÿข Ownership & Registration

OrganizationHostforWeb Support
ASNAS14670
Network Name154.16.116.0 - 154.16.119.255
CIDR Block154.16.116.0/22
RIRAFRINIC
CountryNL
Abuse Contactโ€”

๐ŸŒ DNS Intelligence

PTRpitchmystuff.com
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamespitchmystuff.com

๐Ÿ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown โ€” Insufficient routing data to classify
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
33%
23
routing
13%
11
services
8%
11
ownership
19%
22
reputation
26%
13
geolocation
19%
22
Overall20%912
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Fresh

First Seen2026-05-08 11:09:56 UTC
Last Seen2026-06-26 18:10:41 UTC
Profile Built2026-06-26 00:24:56 UTC
Data FreshnessFresh
Signal Types17
Total Observations18
๐Ÿ” 17 signal types ยท 18 observations collected
This report is generated from 17+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.