# IP Intelligence Briefing: 169.224.0.251/32
## Executive Summary
IP 169.224.0.251 is classified as Low Risk with a risk score of 25/100. The address is owned by ASN 199739 (ae-earthlink-dmcc-1-mnt) within the 169.224.0.0/17 CIDR block. Geolocation data places the IP in Baghdad, Iraq. The endpoint shows no active services (firewalled/no services), no open ports, and no certificate data.
## Ownership & Network Context
- ASN: 199739
- Organization: ae-earthlink-dmcc-1-mnt
- Netname: AE-EARTHLINK-DMCC-19950607
- CIDR Block: 169.224.0.0/17
- RIR: ARIN
- Registration Date: 1995-06-07
- Abuse Contact: Available via RDAP
The IP is associated with the same network entity (AE-EARTHLINK-DMCC-19950607) across all relationship records.
## Threat Indicators
- Blacklist Status: Listed on 8 DNSBL lists with 1 high-severity listing
- Tor Exit: No
- Known Attacker: No
- Spam Source: No
- Campaign Correlation: No associated campaigns detected
The 1 DNSBL listing represents a moderate concern requiring review against threat intelligence feeds, though no active threat indicators (scans, attacks, malicious reputation) are currently present.
## Network Role & Services
- Classification: Firewalled / No Services
- Open Ports: None
- TLS Certificate: None
- HTTP Service: None detected
- Cloud/CDN/Proxy: No
- Is Bogon: No
## Geolocation
- Country: Iraq (IQ)
- City: Baghdad
- Region: Baghdad
- Coordinates: 33.34°N, 44.40°E
- Distance from Reference: 3,675.7 km
- Validation Status: ICMP blocked - unable to validate
## Neighborhood Analysis
The /24 subnet (169.224.0.0/24) contains 4 total sibling IPs:
- Abuse Density: 0%
- Risk Distribution: 2 High (40), 2 Medium (40), 2 Low (25)
- Notable Neighbors: 169.224.0.33 (risk: 40), 169.224.0.114 (risk: 40)
The subnet shows mixed risk levels but maintains low abuse density overall.
## Observation History
12 total observations recorded. Recent signals (2026-07-26 timeframe) indicate:
- Geo-location signals with Baghdad coordinates
- DNSSEC validation: Valid
- ASN resolution: 199739 (Earthlink-DMCC-IQ)
- Blacklist listings with high-severity categories
- No evidence of evolving malicious behavior
## Control Plane
- BGP Prefix: 169.224.0.0/22
- Route Stable: False
- RPKI State: Null
- IRR Consistency: Null
- DNSSEC Valid: True
## SOC Recommendations
1. Monitor DNSBL Listings: Review the 8 blacklist entries, particularly the high-severity listing, to determine relevance to current threat campaigns.
2. Passive Monitoring: No active blocking required; IP shows no services and is firewalled.
3. Subnet Awareness: Monitor neighbors 169.224.0.33 and 169.224.0.114 (risk score 40) for correlated activity.
4. No Immediate Action: Current risk score of 25 falls within acceptable thresholds for standard defensive operations.
## Conclusion
IP 169.224.0.251 represents a low-risk endpoint with no active threat indicators. The primary concern is the blacklist listing requiring intelligence correlation. No immediate defensive actions are warranted beyond standard monitoring protocols.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | ae-earthlink-dmcc-1-mnt |
| ASN | AS199739 |
| Network Name | AE-EARTHLINK-DMCC-19950607 |
| CIDR Block | 169.224.0.0/17 |
| RIR | ARIN |
| Country | IQ |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS199739 |
| Network Prefix | 169.224.0.0/22 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 39% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 20% | 2 | 2 |
| ownership | 17% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 12% | 2 | 2 |
| Overall | 21% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-11 02:17:56 UTC |
| Last Seen | 2026-09-05 16:52:09 UTC |
| Profile Built | 2026-09-05 16:59:40 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 24 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 169.224.0.251
Who owns the IP address 169.224.0.251?
169.224.0.251 is registered to ae-earthlink-dmcc-1-mnt. The address falls within the 169.224.0.0/17 network block. Registration is held at ARIN.
Where is 169.224.0.251 located?
Geolocation data places 169.224.0.251 in Newark, US-NJ, United States. The local time zone is America/New_York. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 169.224.0.251 malicious or safe?
169.224.0.251 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.