Intelligence Briefing: IP 17.166.233.183/32
Subject: Threat Assessment and Ownership Analysis
Date: [Current Date]
Status: Low Risk
Ownership and Identity
Analysis attributed 17.166.233.183 to Apple Inc. (ASN 714, APPLE-WWNET). The address resides within the 17.0.0.0/8 CIDR block. DNS resolution confirmed ownership under apple.com, specifically resolving to 17-166-233-183.applebot.apple.com. Geographic data placed the endpoint in Cupertino, US.
Network State and Services
Network scanning revealed no open ports or active services on the target. The infrastructure type was identified as firewalled. No TLS certificates or HTTP banners were observed.
Threat Indicators and Reputation
The IP exhibited a risk score of 25 (Low Risk). Threat indicators remained empty across all scanned feeds. The endpoint was not flagged as a known attacker, spam source, or Tor exit. Blacklist enumeration returned zero entries. While the control plane noted a single DNSBL listing, the overall reputation classification remained clean.
Neighborhood and Context
The /24 subnet (17.166.233.0/24) was classified as clean with minimal abuse density (0.0072). Out of 139 total siblings, only one threat sibling was identified. The operator score was rated as minimal (0.2174).
Recommendation
The SOC should monitor traffic associated with 17.166.233.183. No immediate blocking or mitigation actions are required. The endpoint is consistent with legitimate Apple botnet activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Apple Inc. |
| ASN | AS714 |
| Network Name | APPLE-WWNET |
| CIDR Block | 17.0.0.0/8 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 17-166-233-183.applebot.apple.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 17-166-233-183.applebot.apple.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Not signed |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 50% | 2 | 3 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 25% | 6 | 7 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-09-24 10:40:04 UTC |
| Last Seen | 2026-09-24 10:40:04 UTC |
| Profile Built | 2026-09-24 10:52:22 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 22 |
Full dossier details are available via our API.