IPDebrief

168.0.226.173

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING

Target: 168.0.226.173/32

Classification: Moderate Risk

Date: 2026-07-25

---

## EXECUTIVE SUMMARY

IP address 168.0.226.173 presents a Moderate Risk profile (Risk Score: 55/100) with elevated operator scoring and DNSBL presence. The IP is attributed to a Brazilian residential or enterprise network operator with no active services. While no direct threat indicators were observed, the IP's route stability issues and DNSBL listings warrant monitoring and defensive blocking.

---

## OWNERSHIP & GEOLOCATION

---

## THREAT ASSESSMENT

Risk Score: 55/100 (Moderate)

Threat Indicators:

DNSBL Presence:

Control Plane Analysis:

---

## NETWORK BEHAVIOR

Geolocation Confidence:

---

## SUBNET NEIGHBORHOOD ANALYSIS

Subnet: 168.0.226.173/24

Abuse Density: 16.67% (0.1667)

Classification: mostly_clean

Inherited Risk: 5/100

Neighboring IP Risk Distribution:

Threat Siblings: 2 IPs in the /24 subnet flagged as threats

---

## OBSERVATION HISTORY

Total Observations: 16 signals captured (2026-07-25)

Recent Signal Types:

Threat Persistence: Not observed (threatPersistenceDays: 0)

Is Persistently Malicious: No

---

## RELATIONSHIP GRAPH

---

## RECOMMENDED ACTIONS

Priority: Increase monitoring and consider blocking

Recommended Firewall Rules:

Monitoring Recommendation: Increase logging verbosity and review recent activity from this IP due to elevated risk score (55/100).

---

## ASSESSMENT

IP 168.0.226.173 is a Brazilian network address with moderate risk characteristics. The combination of DNSBL listings, route instability,

## ASSESSMENT

IP 168.0.226.173 is a Brazilian network address with moderate risk characteristics. The combination of DNSBL listings, route instability, and elevated operator scoring indicates this IP is associated with a low-authority network provider. While no active malicious campaigns were identified, the presence of threat siblings within the /24 subnet suggests this network segment may be used for opportunistic abuse.

Key Risk Factors:

Mitigation Status: No active threat indicators detected. Current profile suggests defensive monitoring and selective blocking may be appropriate for high-value assets.

---

Report Generated: 2026-07-25

Data Sources: IPDebrief Intelligence Platform

Classification: Internal Threat Intelligence (Semi-Confidential)

END OF BRIEFING

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇧🇷 Brazil
RegionSão Paulo
CityLimeira
Timezone—
Latitude-22.61
Longitude-47.38

🏢 Ownership & Registration

OrganizationJOSE APARECIDO PEREIRA DA SILVA TELNET - ME
ASNAS265260
Network Name272294
CIDR Block168.0.224.0/22
RIRARIN
CountryBR
Abuse Contact—

🌐 DNS Intelligence

PTR168-0-226-173.dynamic.telnettelecom.net.br
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnames168-0-226-173.dynamic.telnettelecom.net.br

🔐 DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown — Insufficient routing data to classify
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Server—
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS265260
Network Prefix168.0.226.0/23
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
35%
22
reputation
0%
00
geolocation
25%
11
Overall22%66
Coverage: 5/6 dimensions · Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

📅 Observation Timeline 🔄 Live

First Seen2026-07-09 07:23:29 UTC
Last Seen2026-08-27 05:54:12 UTC
Profile Built2026-08-29 05:39:34 UTC
Data FreshnessLive
Signal Types17
Total Observations19
🔍 17 signal types · 19 observations collected
This report is generated from 17+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 168.0.226.173

Who owns the IP address 168.0.226.173?

168.0.226.173 is registered to JOSE APARECIDO PEREIRA DA SILVA TELNET - ME. The address falls within the 168.0.224.0/22 network block. Registration is held at ARIN.

Where is 168.0.226.173 located?

Geolocation data places 168.0.226.173 in Limeira, São Paulo, Brazil. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 168.0.226.173 malicious or safe?

168.0.226.173 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.

What is the hostname for 168.0.226.173?

The reverse DNS (PTR) record for 168.0.226.173 is 168-0-226-173.dynamic.telnettelecom.net.br. This hostname is not forward-confirmed, so it should be treated as a weak signal.

🏘️ Related IP Addresses

Nearby addresses in 168.0.224.0/22

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.