# IP INTELLIGENCE BRIEFING: 169.224.11.138/32
Classification: LOW RISK
Analysis Date: Current
Data Source: IPDebrief Intelligence Platform
---
## EXECUTIVE SUMMARY
IP address 169.224.11.138 presents a low-risk profile with no active threat indicators. The address is registered to EarthLink DMCC infrastructure in the United Arab Emirates but exhibits no malicious behavior patterns. No services are actively listening on the host, and the IP shows no correlation with known campaigns or threat actors.
---
## PROFILE SUMMARY
Risk Assessment: Low Risk (Score: 25/100)
Ownership: ASN 199739 | ae-earthlink-dmcc-1-mnt | AE-EARTHLINK-DMCC-19950607
Network Block: 169.224.0.0/17 (ARIN)
Geolocation: UAE (Baghdad) | Confidence: 35%
Registration: RIR ARIN | CIDR: 169.224.11.0/24
Key Indicators:
- No blacklist listings (0)
- Not Tor exit node, proxy, or known attacker
- No abuse confidence score available
- DNSBL listed on 1 of 8 threat feeds
---
## NETWORK ACTIVITY & SERVICES
Service Status: FIREWALLED / NO SERVICES DETECTED
- No open ports identified
- No TLS certificates present
- No HTTP/HTTPS banner data
- Zero forward DNS resolution
- No PTR records registered
Network Classification:
- Not cloud, CDN, VPN, proxy, or hosting infrastructure
- Not mobile or residential
- Not bogon or anycast
- Control plane: Route stability flag set to false
---
## THREAT INTELLIGENCE
Threat Indicators: NONE DETECTED
- No active campaigns associated
- No known attacker patterns
- No spam source classification
- Zero honeypot hits
- Zero enumeration strikes
- Zero WAF violations
- Zero total incidents
Control Plane Data:
- DNSBL Listed: 1/8 lists
- Operator Score: 0.1304 (Minimal)
- RPKI State: Not available
- Route Changes (30d): 0
- DNSSEC Valid: Yes
---
## OBSERVATION HISTORY
Total Signals Observed: 14
Analysis Period: Recent monitoring window
Key Historical Findings:
- Most recent geolocation signal: UAE (confidence 0.35)
- Ownership consistently attributed to ae-earthlink-dmcc-1-mnt
- No persistent malicious activity detected
- Some historical geo data showed Iraq (IQ) with Dubai city reference—geo validation flagged as implausible
Temporal Indicators:
- Ownership changes: 0
- Threat persistence days: 0
- Threat observation count: 0
- Is persistently malicious: No
---
## NEIGHBORHOOD ANALYSIS
Subnet: 169.224.11.0/24
Abuse Density: 0
Total Siblings: 6
Neighbor Risk Profile:
| IP Address | Risk Score | Authority Score |
|---|---|---|
| 169.224.11.46 | 25 | 50 |
| 169.224.11.73 | 0 | 50 |
| 169.224.11.87 | 25 | 50 |
| 169.224.11.92 | N/A | N/A |
| 169.224.11.161 | N/A | N/A |
| 169.224.11.178 | N/A | N/A |
Distribution: 0 High Risk, 0 Medium Risk, 3 Low Risk
---
## RELATIONSHIP GRAPH
Connected Entities: 2
- Same Network: AE-EARTHLINK-DMCC-19950607 (appears twice)
- No associated hostnames, certificates, or organizations beyond network block
---
## ACTIONABLE RECOMMENDATIONS
FOR SOC/DEFENSIVE TEAMS:
1. NO IMMEDIATE ACTION REQUIRED — IP shows low-risk profile with no active threats
2. Monitoring Recommendation: Add to passive observation list due to geo-inconsistencies (AE/IQ discrepancies)
3. Firewall Rules: No specific blocking required; standard allow/deny based on policy
4. Investigation Trigger: Monitor for changes if services begin appearing or risk score increases
FIREWALL/IPS RULES:
- No specific iptables/nftables rules generated
- No Cloudflare/AWS WAF rules required
- No nginx/pfSense rules needed
CONTINUOUS MONITORING:
- Track for route stability changes
- Monitor DNSBL listing status
- Watch for service opening on previously firewalled host
---
STATUS: CLEARED FOR NORMAL OPERATIONS
RISK LEVEL: LOW
THREAT CONFIDENCE: LOW
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | ae-earthlink-dmcc-1-mnt |
| ASN | AS199739 |
| Network Name | AE-EARTHLINK-DMCC-19950607 |
| CIDR Block | 169.224.0.0/17 |
| RIR | ARIN |
| Country | IQ |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 0% (None) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS199739 |
| Network Prefix | 169.224.0.0/17 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-06 12:08:32 UTC |
| Last Seen | 2026-10-05 03:18:44 UTC |
| Profile Built | 2026-10-05 03:20:07 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 21 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 169.224.11.138
Who owns the IP address 169.224.11.138?
169.224.11.138 is registered to ae-earthlink-dmcc-1-mnt. The address falls within the 169.224.0.0/17 network block. Registration is held at ARIN.
Where is 169.224.11.138 located?
Geolocation data places 169.224.11.138 in Baghdad, Baghdad, United Arab Emirates. The local time zone is Asia/Dubai. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 169.224.11.138 malicious or safe?
169.224.11.138 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.