# IP Intelligence Briefing: 170.247.3.9
## Executive Summary
IP address 170.247.3.9 is classified as Low Risk with a risk score of 0. The address is owned by IP TECHNOLOGIES S.A.S. (ASN 267788) within the Colombian network block 170.247.0.0/22. While the IP itself shows no direct threat indicators, it resides within a subnet exhibiting 60% abuse density with multiple high-risk neighbors.
## Network Identity & Ownership
- IP Address: 170.247.3.9/32
- Organization: IP TECHNOLOGIES S.A.S.
- ASN: 267788
- CIDR Block: 170.247.0.0/22
- Geolocation: Pasto, Nariño, Colombia (CO)
- Registration Date: 2017-02-08 (via LACNIC)
- Control Plane: Route stable (0 changes in 30 days); DNSSEC valid
## Current Threat Profile
- Risk Score: 0
- Abuse Confidence Score: Not applicable
- Blacklist Status: Clean (0 blacklist entries)
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Services: None detected (firewalled/no services)
- Open Ports: None
## Observations & Historical Signals
Ten observation records indicate consistent network infrastructure characteristics. Recent signals (2026-07-30) confirm:
- DNSSEC validation enabled
- PTR record resolution: None
- Ownership stability: No changes
- Threat persistence: Not observed
- No persistent malicious activity flagged
## Neighborhood Analysis (170.247.3.0/24)
Abuse Density: 0.6 (60%)
| Neighbor IP | Risk Score | Authority Score |
|---|---|---|
| 170.247.3.10 | 80 | 50 |
| 170.247.3.11 | N/A | N/A |
| 170.247.3.12 | 80 | 50 |
| 170.247.3.13 | 80 | 50 |
| 170.247.3.14 | N/A | N/A |
Assessment: Three neighbors in the /24 subnet have high-risk scores (80). This indicates active abuse or malicious activity within the adjacent address space. The subnet classification shows significant inherited risk from neighboring addresses.
## Network Relationships
- Network Association: 170.247.0.0 - 170.247.3.255
- No additional relationships to hostnames, organizations, or certificates beyond network-level association.
## Recommended Security Actions
No specific firewall rules or mitigation recommendations are generated at this time, as the IP address itself presents no direct threat indicators. However, due to the subnet's elevated abuse density, the following contextual considerations apply:
1. Monitor Subnet Activity: While 170.247.3.9 shows no active threats, monitor for any changes in threat profile or emergence of services.
2. Correlate with High-Risk Neighbors: Investigate connections between this IP and high-risk neighbors (170.247.3.10, 170.247.3.12, 170.247.3.13) if traffic patterns suggest lateral movement.
3. Allow List Consideration: Given the low risk score and clean threat profile, this IP may be safely allowed for established communications, pending subnet-level threat emergence.
## Intelligence Conclusion
170.247.3.9 is a low-risk infrastructure address with no active threat indicators. The primary intelligence value lies in contextual awareness of the 170.247.3.0/24 subnet's elevated abuse density. SOC analysts should treat this IP with standard monitoring but maintain awareness of adjacent high-risk addresses that may be part of coordinated abuse campaigns.
Classification: Low Risk (Contextual: Elevated Subnet Risk)
Priority: Monitor
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IP TECHNOLOGIES S.A.S. |
| ASN | AS267788 |
| Network Name | 170.247.0.0 - 170.247.3.255 |
| CIDR Block | 170.247.0.0/22 |
| RIR | ARIN |
| Country | CO |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 8% | 2 | 3 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-28 10:06:18 UTC |
| Last Seen | 2026-08-06 12:47:39 UTC |
| Profile Built | 2026-07-30 16:34:26 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.