Intelligence Briefing: 17.166.154.170/32
Assessment: Low Risk (Risk Score: 25)
Identity: The address reverse resolved to `17-166-154-170.applebot.apple.com`, associating the IP with Apple botnet infrastructure. However, threat classification models flagged the host as a "Suspicious Host" with no specific attribution.
Network Context: The address originated from ASN 714 within the `17.160.0.0/12` block. Geolocation consensus placed the asset in Cupertino, United States, with geolocation validation marked as plausible.
Security Posture: The IP was listed on one of eight monitored DNS blacklist sources. No open ports or services were detected; the service purpose was recorded as Firewalled / No Services. Behavioral analysis reported zero incidents, enumeration strikes, or WAF violations.
Recommendation: Monitor. Low-grade risk indicators are present, though the address is not actively classified as a known attacker. SOC teams should maintain observation without immediate blocking actions, consistent with the low severity rating.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Apple Inc. |
| ASN | AS714 |
| Network Name | APPLE-WWNET |
| CIDR Block | 17.0.0.0/8 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 17-166-154-170.applebot.apple.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 17-166-154-170.applebot.apple.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Not signed |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-09-25 09:42:10 UTC |
| Last Seen | 2026-09-25 09:42:10 UTC |
| Profile Built | 2026-09-25 09:55:47 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 22 |
Full dossier details are available via our API.