Threat Intelligence Briefing: IP 165.154.218.158/32
Entity Overview:
- IP Address: 165.154.218.158/32
- Network Ownership: The IP address is owned by [Owner Information], as identified by WHOIS data.
- Geolocation: The IP is geolocated to [City, Country], based on the most recent geolocation database analysis.
Observation History:
- Recent Activity: The IP address has been observed engaging in [specific activities, such as web traffic, port scanning, or command and control communications], primarily targeting [types of targets, such as financial institutions or government websites].
- Traffic Patterns: Network traffic analysis indicates [description of traffic patterns], with notable spikes in activity occurring [times/dates].
- Anomalous Behavior: Unusual traffic patterns were detected, including [specific anomalies], suggesting potential [malicious or benign] intent.
Relationships and Associations:
- Known Associations: The IP address has been linked to [specific threat actors or campaigns], based on historical data and threat intelligence reports.
- Malware Distribution: There is evidence suggesting that the IP may be involved in distributing [specific malware family or type], as identified by signature matches in malware databases.
- Botnet Activity: Analysis indicates possible involvement in a [botnet or other coordinated attack] infrastructure, with the IP acting as a [command and control node or endpoint].
Neighborhood Data:
- Subnet Analysis: The IP is part of the subnet 165.154.218.0/24. Other IPs within this subnet have been associated with [similar or diverse activities], including [list of activities].
- DNS Records: DNS records show the IP resolving to [domain names], some of which have been flagged in past threat intelligence reports for malicious activities.
- Proximity Threats: Nearby IP addresses have been involved in [types of cyber threats], indicating a potentially risky environment for network interactions.
Threat Assessment:
- Risk Level: [Low/Medium/High] based on the observed activities, associations, and potential impact.
- Recommended Actions:
- Monitor traffic to and from the IP for signs of [specific threats].
- Implement [specific security measures, such as blocking the IP, applying intrusion detection rules, or enhancing endpoint protection].
- Share findings with [relevant stakeholders or threat intelligence communities] to aid in broader threat mitigation efforts.
Conclusion:
The IP address 165.154.218.158/32 presents a [specific level of threat] based on its activities, associations, and network environment. Proactive monitoring and defensive measures are advised to mitigate potential risks. Further investigation into related IPs within the subnet may provide additional insights into ongoing threat activities.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | UCLOUD INFORMATION TECHNOLOGY HK LIMITED |
| ASN | AS135377 |
| Network Name | UCLOUD-US |
| CIDR Block | 165.154.218.0/24 |
| RIR | ARIN |
| Country | US |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_8.0 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 45% | 2 | 5 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 32% | 1 | 4 |
| geolocation | 21% | 2 | 2 |
| Overall | 26% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:03:51 UTC |
| Last Seen | 2026-06-22 19:36:46 UTC |
| Profile Built | 2026-06-22 19:41:02 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 20 |
Full dossier details are available via our API.