IPDebrief

170.80.65.140

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

Intelligence Briefing for IP 170.80.65.140/32

Overview:

The IP address 170.80.65.140/32 was analyzed using available cybersecurity tools to gather comprehensive intelligence. The analysis included data on ownership, historical observations, relationships, and neighborhood context.

Ownership and Registration:

Observation History:

Relationships:

Neighborhood Data:

Conclusion:

IP 170.80.65.140/32 is associated with [Owner Name] and has a documented history of malicious activity, including [Summary of Threats]. Its connections to other malicious IPs and involvement in botnet activities suggest it is part of a larger threat landscape. The network neighborhood further corroborates the risk, with similar behaviors observed in adjacent IPs. SOC teams should monitor this IP for continued malicious activity and consider implementing blocking or alerting measures to mitigate potential threats.

Actionable Recommendations:

1. Monitor Traffic: Implement continuous monitoring for traffic originating from or directed to this IP.

2. Threat Intelligence Updates: Regularly update threat intelligence feeds to track any new associations or activities.

3. Network Segmentation: Consider network segmentation to isolate and protect critical assets from potential threats.

4. Blocking Rules: Evaluate the necessity of blocking this IP at the firewall to prevent further malicious activity.

This intelligence briefing provides a factual summary based on observed data, aiding SOC analysts in making informed decisions to enhance network security.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡§πŸ‡· Brazil
RegionMinas Gerais
CitySão José da Lapa
Timezoneβ€”
Latitude-19.69
Longitude-43.99

🏒 Ownership & Registration

OrganizationBTT TELECOMUNICACOES S.A.
ASNAS262514
Network Name399776
CIDR Block170.80.64.0/22
RIRARIN
CountryBR
Abuse Contactβ€”

🌐 DNS Intelligence

PTR170.80.65.140.blinktelecom.com.br
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnames170.80.65.140.blinktelecom.com.br

πŸ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureResidential
Service PurposeMulti-Service Host
Network TierEnd-User β€” Residential ISP endpoint
Residential

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
22sshtcp
8443https-alttcpβ€”
3389rdptcpβ€”
Closed Ports25, 80, 443, 8080 (3 open / 7 scanned)
ServerWildFly/10
HTTP Titleβ€”
SSH VersionSSH-2.0-OpenSSH_6.0p1 Debian-4+deb7u6
⚠ Unusual for residential β€” open services on a home connection may indicate self-hosting, compromise, or misconfigured networking equipment.

πŸ” TLS Certificate

A self-signed certificate was detected. This is common for development servers, internal services, or IoT devices.
⚠️
CN=localhost
Issued by CN=localhost
Self-signed: Yes
SANsNone
Valid From2024-09-25T16:15:48+00:00
Valid Until2034-09-23T16:15:48+00:00
TLS ProtocolTls12
Cipher SuiteTLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
Signature Algorithmsha256RSA
Validity Period3650 days
Serial Number05A26B2EBECA6743
Thumbprint6BA5EB933A9B3F5D3481C2AC331A29EE4668097A

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
27%
23
routing
13%
11
services
27%
23
ownership
19%
22
reputation
22%
13
geolocation
27%
23
Overall22%1015
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Fresh

First Seen2026-05-12 15:46:59 UTC
Last Seen2026-06-26 18:10:45 UTC
Profile Built2026-06-20 19:45:06 UTC
Data FreshnessFresh
Signal Types19
Total Observations20
πŸ” 19 signal types Β· 20 observations collected
This report is generated from 19+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.