Threat Intelligence Briefing: IP Address 172.104.136.107/32
Overview:
The IP address 172.104.136.107 falls within the private IP address range (172.16.0.0 to 172.31.255.255), typically used for internal network purposes. This range is not routable on the global internet, which implies that it is intended for use within a private network.
Observation History:
- Network Activity: There have been no publicly available records of activity associated with this IP address on the global internet. This is consistent with its classification as a private IP address.
- Public Logs: No public threat intelligence databases or logs indicate any malicious activities or incidents involving this IP address.
- Access Attempts: No evidence of external access attempts or unauthorized access has been reported.
Relationships:
- Ownership: The IP address is not associated with any known public entities, organizations, or individuals. It remains within the scope of private network usage.
- Domain Associations: No domain records or domain name associations have been identified for this IP address.
Neighborhood Data:
- Subnet Analysis: The IP is part of a subnet typically used for internal networking. This suggests it is likely configured for use within an organizationβs local area network (LAN).
- Network Infrastructure: No network infrastructure data, such as routers or switches, has been publicly associated with this IP address.
Security Implications:
- Internal Use: The primary implication is that this IP address is intended for internal use and should be monitored for unauthorized access attempts within the local network.
- Security Measures: Organizations should ensure that proper network segmentation and access controls are in place to prevent internal IP addresses from being exposed to the internet.
Actionable Recommendations:
1. Network Segmentation: Verify that the IP address is correctly segmented within the internal network to prevent exposure to external threats.
2. Access Controls: Implement strict access controls and monitoring to detect any unauthorized access attempts from within the network.
3. Logging and Monitoring: Maintain comprehensive logs and monitoring systems to track any unusual activity related to this IP address within the internal network.
This briefing provides a factual overview based on the available data, focusing on the internal use and security considerations of the IP address 172.104.136.107/32.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Linode |
| ASN | AS63949 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 172-104-136-107.ip.linodeusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 172-104-136-107.ip.linodeusercontent.com |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 23% | 2 | 2 |
| Overall | 20% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-09 11:33:40 UTC |
| Last Seen | 2026-06-27 15:24:04 UTC |
| Profile Built | 2026-06-28 09:30:13 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 26 |
Full dossier details are available via our API.