IP INTELLIGENCE BRIEFING: 168.222.245.11/32
---
EXECUTIVE SUMMARY
IP address 168.222.245.11 is classified as Low Risk with a risk score of 25. The address belongs to the ONEPROVIDER-CA-YVR network under ASN 136258. No active threat indicators, malicious campaigns, or abuse patterns have been observed. Recommended security posture: Monitor or allow.
---
NETWORK IDENTIFICATION
| Attribute | Value |
|---|---|
| IP Address | 168.222.245.11 |
| ASN | 136258 |
| Organization | ONEPROVIDER-CA-YVR |
| RIR | ARIN |
| CIDR Block | 168.222.245.0/24 |
| Country | Canada (CA) |
| Geolocation Confidence | Plausible (3000 km accuracy) |
---
THREAT ASSESSMENT
Risk Profile: Low Risk (Score: 25/100)
| Indicator | Status |
|---|---|
| Known Attacker | No |
| Spam Source | No |
| Tor Exit Node | No |
| DNSBL Listed | 1/8 lists |
| Blacklist Count | 0 |
| Honeypot Hits | 0 |
| WAF Violations | 0 |
| Enumeration Strikes | 0 |
| Threat Persistence Days | 0 |
Threat Indicators: None detected. Empty arrays across all threat feeds, pulsedive risk assessment, and known campaigns.
---
NETWORK CHARACTERISTICS
| Classification | Status |
|---|---|
| Provider | No |
| CDN | No |
| VPN | No |
| Proxy | No |
| Hosting | No |
| Cloud | No |
| Mobile | No |
| Residential | No |
| Services Detected | No open ports |
| DNS Resolution | None |
| PTR Hostnames | None |
Behavioral Analysis: The IP is firewalled with no services exposed. Network scanning indicates 30 traceroute hops with 15 timed-out hops. Transit networks include Comcast. Minimum RTT: 121.6ms.
---
OBSERVATION HISTORY
Signal Count: 15 observations
Recent Signal Types:
- Geolocation inference (Canada, 56.13°N, -106.35°W)
- Ownership data (Abuse contact role object, info@oneprovider.com)
- ASN/RIR registration (ARIN, ONEPROVIDER-CA-YVR)
- Network classification (No CD, Tor, VPN, Cloud, Proxy indicators)
Temporal Trends: No ownership changes. No persistent malicious behavior detected. Threat observation count: 0.
---
NETWORK RELATIONSHIPS
| Relationship Type | Target |
|---|---|
| Same Network | ONEPROVIDER-CA-YVR |
| Same Network | ONEPROVIDER-CA-YVR |
Relationship Count: 2 (Both network-level associations)
---
SUBNET ANALYSIS (168.222.245.0/24)
| Metric | Value |
|---|---|
| Neighbor Count | 0 |
| Abuse Density | 0 |
| High-Risk Siblings | 0 |
| Medium-Risk Siblings | 0 |
| Low-Risk Siblings | 0 |
Classification: Isolated subnet with no observed abuse or threat activity among adjacent addresses.
---
RECOMMENDED ACTIONS
Security Recommendations: None required at this time.
Firewall Rules: No blocking rules recommended.
SOC Guidance: Standard monitoring. This IP exhibits no malicious behavior patterns. If traffic from this address appears in security alerts, verify context against other telemetry before escalation.
---
CONFIDENCE LEVEL
Data Completeness: Full profile retrieved across all intelligence domains (profile, history, relationships, neighborhood, actions).
Observation Quality: 15 historical signals with confidence scores ranging from 0.30 to 0.95.
Assessment: This is a benign infrastructure address with no observable threat indicators.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Abuse contact role object |
| ASN | AS136258 |
| Network Name | ONEPROVIDER-CA-YVR |
| CIDR Block | 168.222.245.0/24 |
| RIR | ARIN |
| Country | CA |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | 1/2 domains |
| DMARC | 2/2 domains |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
| Domains Checked | 2 domains |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | — |
| 22 | ssh | tcp | Banner detected |
| 8443 | https-alt | tcp | — |
| Closed Ports | 25, 80, 3389, 8080 (3 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | wwwqa.microsoft.comwww.microsoft.comstaticview.microsoft.comi.s-microsoft.commicrosoft.comc.s-microsoft.comprivacy.microsoft.com |
| Valid From | 2026-01-22T19:55:21+00:00 |
| Valid Until | 2027-01-17T19:55:21+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384RSA |
| Validity Period | 360 days |
🛡️ Public Network Snapshot
| Origin ASN | AS136258 |
| Network Prefix | 168.222.245.0/24 |
| Route mapping | Found |
| HSTS | Not detected |
| CSP | Not detected |
| HTTP/2 | Not detected |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 35% | 2 | 2 |
| Overall | 18% | 5 | 5 |
| Data Coherence | Mixed Signals (68%) — 2 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
⚠ TLS certificate claims US but primary geo says CA
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-18 11:34:06 UTC |
| Last Seen | 2026-09-01 00:49:23 UTC |
| Profile Built | 2026-08-29 15:39:09 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 24 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 168.222.245.11
Who owns the IP address 168.222.245.11?
168.222.245.11 is registered to Abuse contact role object. The address falls within the 168.222.245.0/24 network block. Registration is held at ARIN.
Where is 168.222.245.11 located?
Geolocation data places 168.222.245.11 in New York. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 168.222.245.11 malicious or safe?
168.222.245.11 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 168.222.245.11?
Responsive ports observed on 168.222.245.11 include 443, 22, 8443. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.