IPDebrief

166.186.196.155

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

Threat Intelligence Briefing: IP Address 166.186.196.155/32

1. IP Address Identification and Ownership:

2. Geolocation and Physical Location:

3. Service and Application Usage:

4. Historical Observations and Traffic Patterns:

5. Relationship and Neighboring Data:

6. Threat Intelligence and Security Incidents:

7. Summary and Recommendations:

- Continue monitoring traffic to and from this IP address for any deviations from expected patterns, which could indicate unauthorized access or misuse.

- Utilize geo-fencing rules in network security devices to ensure that only expected traffic flows from this IP address.

- Maintain updated threat intelligence feeds to promptly identify any new associations or threats related to Microsoft IPs.

This intelligence briefing provides a comprehensive overview of the IP address in question, ensuring SOC analysts have the necessary information to make informed security decisions.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
Regionβ€”
CityTX
Timezoneβ€”
Latitude37.75
Longitude-97.82

🏒 Ownership & Registration

OrganizationAT&T Enterprises, LLC
ASNAS20057
Network Nameβ€”
CIDR Blockβ€”
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRmobile-166-186-196-155.mycingular.net
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamesmobile-166-186-196-155.mycingular.net

πŸ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureResidential
Service PurposeWeb Server
Network TierEnd-User β€” Residential ISP endpoint
MobileResidential

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpβ€”
443httpstcpβ€”
22sshtcp
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”
SSH VersionSSH-2.0-OpenSSH_7.4p1 Debian-10+deb9u3
⚠ Unusual for residential β€” open services on a home connection may indicate self-hosting, compromise, or misconfigured networking equipment.

πŸ” TLS Certificate

An expired certificate for CN=moxa.com, OU=SYS Department, O=MOXA, L=Taipei, S=Taiwan R.O.C, C=TW was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.
⚠️
CN=moxa.com, OU=SYS Department, O=MOXA, L=Taipei, S=Taiwan R.O.C, C=TW
Issued by CN=moxa.com, OU=SYS Department, O=MOXA, L=Taipei, S=Taiwan R.O.C, C=TW
Self-signed: Yes
SANsNone
Valid From2018-11-06T09:08:21+00:00
Valid Until2019-11-06T09:08:21+00:00 (expired)
TLS ProtocolTls12
Cipher SuiteTLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
Signature Algorithmsha256RSA
Validity Period365 days
Serial Number00A2BA3D380BCEE21E
ThumbprintEEA9432BD1114996A646289527F38BB9334044CE

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
19%
22
routing
8%
11
services
8%
11
ownership
27%
23
reputation
13%
12
geolocation
19%
22
Overall16%911
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceMixed Signals (68%) β€” 2 contradiction(s)
AttributionModerate (55%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Geo sources disagree on country: TW, US
⚠ TLS certificate claims TW but primary geo says US

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-08 17:17:41 UTC
Last Seen2026-06-25 08:28:46 UTC
Profile Built2026-06-25 08:47:42 UTC
Data FreshnessLive
Signal Types20
Total Observations21
πŸ” 20 signal types Β· 21 observations collected
This report is generated from 20+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.