# IP Intelligence Briefing: 154.219.112.227/32
## Executive Summary
IP 154.219.112.227 presents a LOW RISK threat profile with an overall risk score of 25. The address is registered to Cloud Innovation Support (ASN 401701) within the 154.219.112.0/24 block. No active malicious campaigns or blacklist associations have been identified. The IP maintains minimal neighborhood abuse density and shows stable, single-service host characteristics.
## Ownership and Infrastructure
- Organization: Cloud Innovation Support
- ASN: 401701
- CIDR Block: 154.219.112.0 - 154.219.112.255 (/24)
- RIR: afrinic
- Network Classification: Single-Service Host
- DNSBL Listings: 1 of 8 threat feeds (minimal operator score: 0.1304)
## Network Services and Fingerprinting
- Open Ports: TCP/22 (SSH)
- SSH Banner: SSH-2.0-OpenSSH_9.2p1 Debian-2
- Infrastructure Flags: Not cloud, CDN, VPN, proxy, Tor, or hosting infrastructure
- Control Plane: Route-stable (0 changes in 30 days), DNSSEC valid
## Geolocation Intelligence
Geolocation data shows significant inconsistency across multiple observation points:
- Primary consensus: United States (US)
- Historical observations: Seychelles (22.2578°S, 114.1657°E) and Hong Kong (HK)
- Measured distance: 9,175 km from observation point
- Average RTT: 294.6ms (minimum possible: 183.5ms)
- Traceroute: 15 hops via Comcast and NTT transit networks
This geographic variance warrants monitoring but does not indicate confirmed spoofing at this risk level.
## Threat Indicators
- Risk Score: 25 (Low Risk)
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Blacklist Count: 0
- Threat Persistence: 0 days
- Campaign Correlation: None
## Neighborhood Analysis
The /24 subnet (154.219.112.0/24) demonstrates a CLEAN classification:
- Abuse Density: 0
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 0
- Risk Distribution: No high or medium-risk neighbors identified
## Observation History Summary
16 observations recorded. Recent activity (July 30, 2026) shows:
- ASN and RIR registration data from afrinic
- Multiple geolocation signals with inconsistent country assignments
- Traceroute validation with 15 hops
- RTT measurements consistent with transcontinental distance
- No new threat indicators emerged
## Relationship Graph
Single relationship identified: Same Network (154.219.112.0 - 154.219.112.255). No additional links to organizations, hostnames, or certificates.
## Recommended Actions
Based on current risk assessment (score 25), no immediate firewall rules or blocking actions are recommended. The IP does not meet thresholds for automatic remediation. Monitor for:
- New blacklist associations
- Geolocation pattern changes
- Emergence of malicious indicators
## SOC Analyst Notes
This IP appears to be a legitimate, low-risk endpoint with standard SSH service exposure. The geolocation inconsistencies are noted but fall within acceptable variance for distributed infrastructure. No immediate threat mitigation required. Continue passive monitoring for threat indicator emergence.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Cloud Innovation Support |
| ASN | AS401701 |
| Network Name | 154.219.112.0 - 154.219.112.255 |
| CIDR Block | 154.219.112.0/24 |
| RIR | AFRINIC |
| Country | HK |
| Abuse Contact | β |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.2p1 Debian-2 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 35% | 2 | 2 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 18% | 5 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-29 04:29:57 UTC |
| Last Seen | 2026-08-02 10:53:24 UTC |
| Profile Built | 2026-07-30 19:54:41 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 18 |
Full dossier details are available via our API.