# IP INTELLIGENCE BRIEFING: 170.0.62.173/32
Date: July 2026
Classification: Moderate Risk - Residential Infrastructure
---
## EXECUTIVE SUMMARY
IP 170.0.62.173 is a Brazilian residential IP address (Surubim, Pernambuco) associated with ASN 265008 (T F DA SILVA RAMOS TELECOMUNICAÇÕES E SISTEMA EPP). Risk score of 50 indicates moderate threat level. The IP hosts standard residential services (SSH on port 22, HTTP-alt on port 8080) and is listed on 2 of 8 DNS blacklist entries. No active threat campaigns or known attacker indicators detected.
---
## INFRASTRUCTURE PROFILE
Network Classification:
- ASN: 265008
- Organization: T F DA SILVA RAMOS TELECOMUNICAÇÕES E SISTEMA EPP
- CIDR: 170.0.60.0/22
- Subnet: 170.0.62.173/24
- Infrastructure Type: Residential
- Network Role: Multi-Service Host
Geolocation:
- Country: Brazil (BR)
- Region: Pernambuco
- City: Surubim
- Geolocation Confidence: Consensus validated but RTT validation anomalies detected
Active Services:
- Port 22/TCP: SSH (OpenSSH 9.2p1 Debian-2+deb12u10)
- Port 8080/TCP: HTTP-alt
---
## THREAT INTELLIGENCE
Risk Assessment:
- Overall Risk Score: 50 (Moderate)
- Abuse Confidence: Not explicitly flagged
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Cloud/Proxy/VPN: No
Blacklist Status:
- DNSBL Listings: 2 of 8 lists
- Provider Score: 0
- Authority Score: 0
- RPKI State: Not validated
Threat Indicators:
- No known threat feeds matched
- No active campaign associations
- No certificate-based threat matches
- No correlated malicious IPs
---
## OBSERVATION HISTORY
Signal Timeline: 15 observations recorded
- Recent activity concentrated in July 2026
- Geo validation anomalies: RTT measurements (116-127ms) below minimum possible for Brazil distance (7,814km)
- No persistent malicious behavior detected
- No ownership changes observed
- Threat observation count: 0
- Persistence days: 0
Signal Confidence:
- Network classification: 0.40 confidence
- Port scanning: 0.90 confidence
- Ownership verification: 0.85 confidence
---
## NETWORK RELATIONSHIPS & NEIGHBORHOOD
Related Entities:
- 2 relationships identified (same network 282407)
Subnet Analysis (170.0.62.173/24):
- Total Neighbors: 2
- Risk Distribution: 2 medium risk, 0 high risk, 0 low risk
- Abuse Density: 0
- Neighbor IPs:
- 170.0.62.165 (Risk: 50, Authority: 50)
- 170.0.62.246 (Risk: 50, Authority: 50)
BGP/Route Stability:
- Route stability: False
- Route changes (30d): 0
- Origin ASN: 265008
- BGP Prefix: 170.0.62.0/23
---
## RECOMMENDED ACTIONS
Firewall Rule Recommendations:
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 170.0.62.173 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 170.0.62.173 drop` |
| nginx | `deny 170.0.62.173;` |
| pfSense | `170.0.62.173/32` |
| Cloudflare WAF | Block IP with risk score 50 |
| AWS WAF | Block address 170.0.62.173/32 |
SOC Analyst Notes:
- Residential IP with moderate risk score
- SSH service exposed may indicate home user or small business infrastructure
- DNSBL listings warrant investigation if inbound connections observed
- Consider subnet-level monitoring given 2 medium-risk neighbors
- No immediate threat indicators, but maintain monitoring for behavioral changes
---
Data Sources: IPDebrief Intelligence Platform
Classification: DEFENSIVE SECURITY INTELLIGENCE
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | T.I Connect LTDA |
| ASN | AS265008 |
| Network Name | 282407 |
| CIDR Block | 170.0.60.0/22 |
| RIR | ARIN |
| Country | BR |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 0% (None) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Residential |
| Service Purpose | Multi-Service Host |
| Network Tier | End-User — Residential ISP endpoint |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | Banner detected |
| 8080 | http-alt | tcp | — |
| Closed Ports | 25, 80, 443, 3389, 8443 (2 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS265008 |
| Network Prefix | 170.0.62.0/23 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 22% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 28% | 2 | 5 |
| reputation | 20% | 1 | 4 |
| geolocation | 20% | 2 | 3 |
| Overall | 18% | 10 | 19 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-13 09:17:07 UTC |
| Last Seen | 2026-09-29 03:06:46 UTC |
| Profile Built | 2026-09-27 14:43:27 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 26 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 170.0.62.173
Who owns the IP address 170.0.62.173?
170.0.62.173 is registered to T.I Connect LTDA. The address falls within the 170.0.60.0/22 network block. Registration is held at ARIN.
Where is 170.0.62.173 located?
Geolocation data places 170.0.62.173 in Surubim, Pernambuco, Brazil. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 170.0.62.173 malicious or safe?
170.0.62.173 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 170.0.62.173?
Responsive ports observed on 170.0.62.173 include 22, 8080. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.
Is 170.0.62.173 a VPN, proxy, or data center address?
170.0.62.173 is classified as a residential network based on network ownership and behavioural analysis.