INTELLIGENCE BRIEFING: 162.214.229.171
Classification: Defensive Threat Intelligence | Risk Level: LOW
1. EXECUTIVE SUMMARY
The target IP 162.214.229.171 presents a low-risk profile with a risk score of 25/100. The address is associated with Unified Layer (ASN 31898) infrastructure in Phoenix, Arizona. While the IP shows no active malicious indicators currently, historical data indicates one DNSBL listing event with high severity rating during June 2026. No ongoing threat campaigns or persistent malicious behavior observed.
2. OWNERSHIP AND INFRASTRUCTURE
- ISP/Provider: Unified Layer (ASN 31898)
- Geolocation: United States, Arizona, Phoenix (±2500km accuracy)
- BGP Prefix: 162.214.224.0/21
- Route Stability: Unstable (isRouteStable: false)
- Service Classification: Firewalled / No Services
- DNS Resolution: server.ozaas.com (ozaas.com domain)
- Open Ports: None detected
3. THREAT INTELLIGENCE PROFILE
- Overall Risk Score: 25/100 (Low Risk)
- Abuse Confidence Score: Not calculated
- Blacklist Status: 0 blacklists (current), 1 historical DNSBL listing
- Threat Indicators: None active
- Known Campaigns: None detected
- Tor/VPN/Proxy: Negative on all vectors
- Hosting/Residential: Negative classification
4. HISTORICAL OBSERVATION ANALYSIS
Analysis of 20 historical signals reveals the following timeline:
- June 2, 2026: DNSBL listing activity observed (8 total lists, 1 active listing, maximum severity: high). This represented the primary risk event for this IP.
- June 17, 2026: Recent observation showing minimal operator score (0.1304) and stable reputation signals.
- Temporal Persistence: No persistent malicious behavior detected. Threat observation count: 1.
5. NETWORK RELATIONSHIPS
- Network Affiliation: 13 relationships mapped to UNIFIEDLAYER-NETWORK-15
- DNS Associations: 13 relationships to server.ozaas.com hostname
- Control Plane: Operator score 0.1304 (Minimal), RPKI state not reported, IRR consistency not reported
6. SUBNET ANALYSIS (162.214.229.0/24)
- Abuse Density: 1
- Classification: mostly_clean
- Inherited Risk: 2
- Threat Siblings: 1 (1 active threat sibling identified in subnet)
- Total Siblings: 1
7. SECURITY ACTIONS RECOMMENDATION
- Risk Level: LOW
- Action Required: No immediate firewall rules or blocking recommended
- Monitoring: Standard monitoring advised given historical DNSBL activity
- Firewall Rules: Not generated (risk score below threshold)
8. INTELLEIGENCE ASSESSMENT
The IP 162.214.229.171 should be classified as low-risk with monitoring only. The single historical DNSBL listing event appears isolated and does not indicate persistent malicious activity. The infrastructure is associated with a legitimate cloud hosting provider (Unified Layer). No evidence of command-and-control, spam source, or attack infrastructure.
RECOMMENDED SOC ACTION: Maintain standard monitoring. No blocking required. Add to watchlist only if new threat indicators emerge in subsequent observations.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Unified Layer |
| ASN | AS31898 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | server.ozaas.com |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | server.ozaas.com |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 24% | 2 | 3 |
| reputation | 24% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 18% | 9 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:03:50 UTC |
| Last Seen | 2026-06-22 19:21:44 UTC |
| Profile Built | 2026-06-22 19:26:47 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.