# IP Intelligence Briefing: 168.167.23.14/32
Classification: Moderate Risk | Risk Score: 55/100
Date: 2026-07-22 | Status: Active Monitoring
---
## Executive Summary
IP 168.167.23.14 exhibits a moderate risk profile with no confirmed active threats. The address is geolocated to Botswana (BW) and operates with firewalled/no services configuration. No malicious indicators, blacklists, or threat campaigns detected. Neighborhood analysis indicates a clean subnet with minimal abuse density.
---
## Technical Profile
Geolocation:
- Country: Botswana (BW)
- Region/City: Gaborone
- Coordinates: -24.64, 25.91
Network Classification:
- ASN: 14988
- BGP Prefix: 168.167.23.0/24
- Service Purpose: Firewalled / No Services
- No open ports detected
Risk Metrics:
- Overall Risk Score: 55
- Provider Score: 0
- Authority Score: 0
- Operator Score: 0.1304 (Minimal)
- Abuse Confidence Score: None
---
## Threat Assessment
Malicious Indicators: None Detected
- Not a known attacker or spam source
- Not a Tor exit node, proxy, or VPN
- No threat feed matches
- No known campaign associations
Blacklist Status:
- DNSBL Listed: 3 of 8 lists
- Abuse confidence: Inconclusive
Control Plane Observations:
- DNSSEC Valid: Yes
- Route Stability: False (0 route changes in 30d)
- MOAS Status: False
---
## Neighborhood Analysis
Subnet: 168.167.23.0/24
- Abuse Density: 0 (Clean)
- Total Siblings: 4
- Threat Siblings: 0
- Classification: Clean
Neighbor Risk Distribution:
- High Risk: 0
- Medium Risk: 0
- Low Risk: 2
Adjacent IPs (168.167.23.56, 168.167.23.93, 168.167.23.111) show no malicious activity.
---
## Historical Observations
Monitoring Period: 11 observations (2026-07-22)
Signal Evolution:
- Recent subnet classification: Clean (abuse density: 0)
- Infrastructure type: Non-CDN, non-Tor, non-VPN
- Ownership changes: 0
- Threat persistence: 0 days
- HTTP responses: 404 (not serving web content)
Temporal Indicators:
- Threat observation count: 0
- Persistently malicious: False
- Is active attacker: False
---
## Relationships & Intelligence Links
- External Relationships: None detected
- Certificate Associations: None
- Hostname Associations: None
- Organizational Links: None
---
## Recommended Actions
Firewall Policy: Monitor
- No immediate blocking required
- Log connection attempts for baseline analysis
- Apply standard egress filtering
IOC Generation: Not Recommended
- No actionable threat indicators present
- Low priority for IOC creation
SOC Guidance:
- IP shows no active malicious behavior
- Moderate risk score reflects limited intelligence, not confirmed threat
- Monitor for changes in service configuration or blacklist additions
- No correlation with known threat campaigns
---
Analyst Notes: This IP demonstrates a moderate risk profile primarily due to limited intelligence data rather than confirmed malicious activity. The subnet shows clean characteristics with no neighborhood threats. Recommend periodic re-evaluation as network behavior may change.
Confidence Level: Medium
Last Updated: 2026-07-22 08:24 UTC
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Unknown |
| ASN | — |
| Network Name | — |
| CIDR Block | — |
| RIR | — |
| Country | — |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS14988 |
| Network Prefix | 168.167.23.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Low (30%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-02 04:21:09 UTC |
| Last Seen | 2026-08-22 10:23:21 UTC |
| Profile Built | 2026-08-29 11:07:25 UTC |
| Data Freshness | Live |
| Signal Types | 13 |
| Total Observations | 14 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 168.167.23.14
Where is 168.167.23.14 located?
Geolocation data places 168.167.23.14 in Gaborone, Gaborone, BW. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 168.167.23.14 malicious or safe?
168.167.23.14 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.