IPDebrief

168.222.245.11

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

IP INTELLIGENCE BRIEFING: 168.222.245.11/32

---

EXECUTIVE SUMMARY

IP address 168.222.245.11 is classified as Low Risk with a risk score of 25. The address belongs to the ONEPROVIDER-CA-YVR network under ASN 136258. No active threat indicators, malicious campaigns, or abuse patterns have been observed. Recommended security posture: Monitor or allow.

---

NETWORK IDENTIFICATION

AttributeValue
IP Address168.222.245.11
ASN136258
OrganizationONEPROVIDER-CA-YVR
RIRARIN
CIDR Block168.222.245.0/24
CountryCanada (CA)
Geolocation ConfidencePlausible (3000 km accuracy)

---

THREAT ASSESSMENT

Risk Profile: Low Risk (Score: 25/100)

IndicatorStatus
Known AttackerNo
Spam SourceNo
Tor Exit NodeNo
DNSBL Listed1/8 lists
Blacklist Count0
Honeypot Hits0
WAF Violations0
Enumeration Strikes0
Threat Persistence Days0

Threat Indicators: None detected. Empty arrays across all threat feeds, pulsedive risk assessment, and known campaigns.

---

NETWORK CHARACTERISTICS

ClassificationStatus
ProviderNo
CDNNo
VPNNo
ProxyNo
HostingNo
CloudNo
MobileNo
ResidentialNo
Services DetectedNo open ports
DNS ResolutionNone
PTR HostnamesNone

Behavioral Analysis: The IP is firewalled with no services exposed. Network scanning indicates 30 traceroute hops with 15 timed-out hops. Transit networks include Comcast. Minimum RTT: 121.6ms.

---

OBSERVATION HISTORY

Signal Count: 15 observations

Recent Signal Types:

Temporal Trends: No ownership changes. No persistent malicious behavior detected. Threat observation count: 0.

---

NETWORK RELATIONSHIPS

Relationship TypeTarget
Same NetworkONEPROVIDER-CA-YVR
Same NetworkONEPROVIDER-CA-YVR

Relationship Count: 2 (Both network-level associations)

---

SUBNET ANALYSIS (168.222.245.0/24)

MetricValue
Neighbor Count0
Abuse Density0
High-Risk Siblings0
Medium-Risk Siblings0
Low-Risk Siblings0

Classification: Isolated subnet with no observed abuse or threat activity among adjacent addresses.

---

RECOMMENDED ACTIONS

Security Recommendations: None required at this time.

Firewall Rules: No blocking rules recommended.

SOC Guidance: Standard monitoring. This IP exhibits no malicious behavior patterns. If traffic from this address appears in security alerts, verify context against other telemetry before escalation.

---

CONFIDENCE LEVEL

Data Completeness: Full profile retrieved across all intelligence domains (profile, history, relationships, neighborhood, actions).

Observation Quality: 15 historical signals with confidence scores ranging from 0.30 to 0.95.

Assessment: This is a benign infrastructure address with no observable threat indicators.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇨🇦 Canada
Region—
CityNew York
Timezone—
Latitude—
Longitude—

🏢 Ownership & Registration

OrganizationAbuse contact role object
ASNAS136258
Network NameONEPROVIDER-CA-YVR
CIDR Block168.222.245.0/24
RIRARIN
CountryCA
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)

🔐 DNS Hygiene

Hygiene Score60% (Good)
SPF1/2 domains
DMARC2/2 domains
FCrDNSNot verified
DNSSECValid
CAANot configured
Domains Checked2 domains

☁️ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierUnknown — Insufficient routing data to classify
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
443httpstcp—
22sshtcpBanner detected
8443https-alttcp—
Closed Ports25, 80, 3389, 8080 (3 open / 7 scanned)
ServerWeb server detected
HTTP Title—

🔐 TLS Certificate

🔒
CN=www.microsoft.com, O=Microsoft Corporation, L=Redmond, S=WA, C=US
Issued by CN=Microsoft TLS G2 RSA CA OCSP 04, O=Microsoft Corporation, C=US
Self-signed: No
SANswwwqa.microsoft.comwww.microsoft.comstaticview.microsoft.comi.s-microsoft.commicrosoft.comc.s-microsoft.comprivacy.microsoft.com
Valid From2026-01-22T19:55:21+00:00
Valid Until2027-01-17T19:55:21+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha384RSA
Validity Period360 days

🛡️ Public Network Snapshot

Origin ASNAS136258
Network Prefix168.222.245.0/24
Route mappingFound
HSTSNot detected
CSPNot detected
HTTP/2Not detected

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
0%
00
reputation
0%
00
geolocation
35%
22
Overall18%55
Coverage: 4/6 dimensions · Data sufficiency: partial
Data CoherenceMixed Signals (68%) — 2 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Geo sources disagree on country: US, CA
⚠ TLS certificate claims US but primary geo says CA

📅 Observation Timeline 🔄 Live

First Seen2026-07-18 11:34:06 UTC
Last Seen2026-09-01 00:49:23 UTC
Profile Built2026-08-29 15:39:09 UTC
Data FreshnessLive
Signal Types22
Total Observations24
🔍 22 signal types · 24 observations collected
This report is generated from 22+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 168.222.245.11

Who owns the IP address 168.222.245.11?

168.222.245.11 is registered to Abuse contact role object. The address falls within the 168.222.245.0/24 network block. Registration is held at ARIN.

Where is 168.222.245.11 located?

Geolocation data places 168.222.245.11 in New York. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 168.222.245.11 malicious or safe?

168.222.245.11 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.

What ports are open on 168.222.245.11?

Responsive ports observed on 168.222.245.11 include 443, 22, 8443. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.

🏘️ Related IP Addresses

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.