# Threat Intelligence Briefing: 170.187.165.139
Classification: Moderate Risk | Data Sources: IPDebrief Intelligence Platform | Analysis Date: Current
## Executive Summary
IP address 170.187.165.139 is a Linode cloud infrastructure endpoint with moderate risk characteristics. The IP is associated with a single DNS hostname (baku.scan.bufferover.run) and resolves to a bufferover.run domain. While the local /24 subnet maintains a clean classification with zero abuse density, the IP registers on two DNSBL lists, warranting monitoring.
## Technical Profile
Network Context:
- Organization: Linode LLC (AS63949)
- CIDR Block: 170.187.128.0/17
- Infrastructure Type: CloudCompute with Hosting capabilities enabled
- Geolocation: United States, New Jersey region
- Connection Status: Firewalled with no active open ports
DNS Analysis:
- PTR Record: baku.scan.bufferover.run
- Forward Resolution: bufferover.run (1 confirmed entry)
- Email Auth: SPF enabled, DMARC absent
- DNSBL Status: Listed on 2 of 8 threat feeds
Control Plane:
- BGP Prefix: 170.187.160.0/21
- Route Stability: Unstable (route changes observed in 30-day window)
- DNSSEC: Valid
- Operator Score: 0.2609 (Basic classification)
## Threat Assessment
Current Risk Profile:
- Risk Score: 50 (Moderate)
- Abuse Confidence Score: Not applicable
- Threat Indicators: None identified
- Campaign Association: None detected
- Tor/Proxy Status: Negative across all indicators
Historical Observations:
- Total Signals: 22 observations recorded
- Recent Activity: 2026-08-13 (multiple signals)
- Threat Persistence: No persistent malicious activity detected
- Neighborhood Context: /24 subnet classified as "clean" with 0 abuse density
Relationship Network:
- DNS Associations: Multiple entries linking to baku.scan.bufferover.run
- Network Affiliations: LINODE network (170.187.165.0/24)
- Correlated Entities: No additional threat-linked entities identified
## Neighborhood Analysis
Subnet Profile (170.187.165.0/24):
- Total Siblings: 2
- Active Siblings: 2
- Threat Siblings: 0
- Abuse Density: 0%
Neighbor Assessment:
- 170.187.165.130: Risk Score 25, Authority Score 60 (Low risk)
## Recommended Actions
1. Monitor DNS resolution activity to bufferover.run subdomains
2. Observe for any new open ports or service changes
3. Review traffic patterns associated with DNSBL listings
4. No immediate blocking recommended; maintain logging and monitoring
## Intelligence Narrative
The target IP operates within Linode's cloud infrastructure and presents moderate risk primarily due to DNSBL listings. The absence of open ports, no active threat indicators, and clean neighborhood classification suggest the IP may be engaged in legitimate hosting or scanning activity rather than active exploitation. The DNS association with bufferover.run requires attention, as this domain is commonly used for security scanning operations. Historical data shows no escalation in threat behavior over the observation period.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Linode |
| ASN | AS63949 |
| Network Name | LINODE |
| CIDR Block | 170.187.128.0/17 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | baku.scan.bufferover.run |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | baku.scan.bufferover.run |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 17% | 1 | 1 |
| Overall | 24% | 9 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-08-05 18:27:56 UTC |
| Last Seen | 2026-08-13 07:58:57 UTC |
| Profile Built | 2026-08-13 08:12:45 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 24 |
Full dossier details are available via our API.