INTELLIGENCE BRIEFING: 172.104.186.246/32
1. EXECUTIVE SUMMARY
IP 172.104.186.246 is a low-risk cloud infrastructure endpoint associated with Linode (ASN 63949) located in Singapore. The IP demonstrates benign operational characteristics with no active threat indicators. Risk score: 25/100. Classification: CloudCompute/Hosting infrastructure.
2. OWNERSHIP AND INFRASTRUCTURE
- Provider: Linode (Cloud hosting provider)
- ASN: 63949
- Infrastructure Type: Cloud Compute / Hosting
- Geolocation: Singapore (SG)
- CIDR Block: 172.104.160.0/19
- Ownership: Stable (0 ownership changes observed)
- Network Classification: Firewalled / No Services
3. THREAT INDICATORS
- Abuse Confidence: Not detected
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0
- DNSBL Listed Count: 1
- Threat Persistence: 0 days
- Persistently Malicious: False
4. DNS AND RESOLUTION
- PTR Hostname: 172-104-186-246.ip.linodeusercontent.com
- Forward Resolution: Confirmed
- Hosted Domains: None (0)
- Email Authentication: No SPF, No DMARC records
- TLS Certificates: None detected
- Active Services: No open ports, no HTTP/HTTPS services detected
5. NEIGHBORHOOD ANALYSIS (172.104.186.0/24 subnet)
- Subnet Classification: Mostly Clean
- Abuse Density: 0
- Total Siblings: 3
- Active Siblings: 2
- Threat Siblings: 3
- Sibling IPs:
- 172.104.186.23: Risk Score 25, Authority Score 60
- 172.104.186.73: Risk Score 49, Authority Score 60
- Inherited Risk Score: 7
6. OBSERVATION HISTORY (22 total signals)
Recent observations (as of 2026-06-20) indicate:
- Abuse density: 1 (consistent with low-risk profile)
- No recent threat observations beyond single count
- Operator score: 0.2609 (Basic classification)
- No significant risk trend changes
7. RELATIONSHIP GRAPH (41 total relationships)
- DNS Association: 172-104-186-246.ip.linodeusercontent.com
- Multiple network associations with LINODE infrastructure
- 36 additional relationships (primarily network-level associations)
8. RECOMMENDATIONS
Based on the risk profile (25/100), no immediate blocking or mitigation actions are required. The IP is a standard cloud hosting endpoint with no malicious indicators. Continue monitoring as part of normal operational procedures.
9. ANALYST NOTES
This IP represents routine cloud infrastructure activity. The low-risk score, lack of open services, and clean neighborhood profile indicate normal operation. No escalation or investigation recommended at this time.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Linode |
| ASN | AS63949 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 172-104-186-246.ip.linodeusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 172-104-186-246.ip.linodeusercontent.com |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 34% | 2 | 5 |
| ownership | 20% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 25% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-16 14:58:08 UTC |
| Last Seen | 2026-06-28 03:35:57 UTC |
| Profile Built | 2026-06-28 21:39:49 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 28 |
Full dossier details are available via our API.