Threat Intelligence Briefing: IP 165.154.6.224/32
Summary:
The IP address 165.154.6.224/32 was observed across multiple data sources, revealing its involvement in various network activities. This briefing outlines key findings related to the IPโs profile, observation history, relationships, and neighborhood data, providing actionable insights for SOC analysts.
Profile:
- Owner Information: The IP address is registered to [Entity Name], located in [Country]. The registration details indicate it is used for [Purpose/Industry].
- ASN: The IP is associated with Autonomous System Number [ASN], operated by [ASN Owner], suggesting it is part of a network infrastructure managed by this entity.
Observation History:
- Activity Patterns: The IP has been active predominantly during [Timeframe], with peak usage observed in [Time Window]. This pattern suggests [Inferred Activity Type].
- Traffic Volume: Analysis of traffic data indicates a consistent flow of [Volume Type] traffic, primarily directed towards [Destinations] and originating from [Sources].
- Geographic Distribution: Traffic from this IP has been observed originating from [Regions/Countries], indicating a wide geographic distribution of its users.
Relationships:
- Known Associations: The IP has been identified in connections with other IPs within [Related Networks/Entities], suggesting a collaborative or shared operational environment.
- Malicious Indicators: The IP has been flagged in threat intelligence databases for associations with [Specific Threat Types], such as [Malware Family] and [Phishing Campaigns].
- Domain Associations: The IP resolves to domains that have been linked to [Malicious/Questionable Activities], including [Specific Domain Names].
Neighborhood Data:
- Subnet Analysis: The IP is part of a subnet [Subnet Range] that includes other IPs with a history of [Behavior Type], such as [Malicious/Unusual Activities].
- Proximity to Known Threats: Neighboring IPs have been implicated in [Specific Threat Types], indicating a potentially compromised or targeted network segment.
- Security Events: Historical security incidents in the vicinity include [Incident Types], such as [Distributed Denial of Service (DDoS) Attacks] and [Data Exfiltration Attempts].
Actionable Insights:
- Monitoring: Increase monitoring of traffic originating from and directed towards 165.154.6.224/32, focusing on [Specific Traffic Types] and [Time Windows].
- Investigation: Investigate connections with associated IPs and domains for potential security breaches or malicious activities.
- Mitigation: Consider implementing additional security measures, such as [Firewall Rules/Intrusion Detection Systems], to mitigate potential threats from this IP address.
This intelligence briefing provides a comprehensive overview of the IP address 165.154.6.224/32, offering actionable insights for SOC analysts to enhance network defense strategies.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | UCLOUD INFORMATION TECHNOLOGY HK LIMITED |
| ASN | AS135377 |
| Network Name | โ |
| CIDR Block | 165.154.6.0/24 |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 19% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 19% | 2 | 2 |
| Overall | 18% | 10 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-10 04:11:34 UTC |
| Last Seen | 2026-06-25 22:27:02 UTC |
| Profile Built | 2026-06-25 22:43:29 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 20 |
Full dossier details are available via our API.