IPDEBRIEF INTELLIGENCE BRIEFING
Target: 172.104.55.33/32
Classification: Cloud Infrastructure IP β Moderate Risk
---
PROFILING SUMMARY
The target IP address 172.104.55.33 belongs to Linode (AS63949), a cloud hosting provider operating from Singapore. The IP is classified as cloud compute infrastructure with a risk score of 50 (Moderate Risk). DNS resolution confirmed the address resolves to 172-104-55-33.ip.linodeusercontent.com with forward confirmation verified. No open ports or active services were detected on the target.
OWNERSHIP & INFRASTRUCTURE
| Attribute | Value |
|---|---|
| ASN | 63949 (Linode) |
| Organization | LINODE |
| CIDR Block | 172.104.0.0/16 |
| Geolocation | Singapore (SG) |
| Infrastructure Type | CloudCompute |
| DNSBL Listings | 8 total (2 high severity) |
THREAT ASSESSMENT
The IP maintains a moderate risk profile with no active threat indicators detected. The address is not classified as a Tor exit node, known attacker, or spam source. The control plane indicates the IP is listed on 8 DNSBLs, with 2 listings flagged as high severity. No known malware campaigns correlate with this address.
NEIGHBORHOOD ANALYSIS
The /24 subnet (172.104.55.0/24) contains 2 active sibling IPs with an abuse density of 0. One neighboring IP (172.104.55.192) also carries a risk score of 50 with an authority score of 60. The subnet is classified as clean with no inherited threat risk.
OBSERVATION HISTORY
Historical analysis returned 23 observations. Key temporal signals indicate subnet abuse density fluctuated between 0 and 0.5 during the observation window. Routing stability remains inconsistent, with route changes recorded within the 30-day period. Geolocation data consistently validated Singapore location with RTT measurements between 246-260ms.
RELATIONSHIP MAPPING
The IP exhibits 18 relationships, primarily DNS associations to the Linode hostname and network associations to the LINODE organization. No unique certificate subjects or correlated external IPs were identified in the relationship graph.
RECOMMENDED ACTIONS
Based on the moderate risk profile, the following actions are recommended:
- Firewall: Block traffic to/from 172.104.55.33/32
- iptables: `iptables -A INPUT -s 172.104.55.33 -j DROP`
- Cloudflare WAF: Block with expression `ip.src eq 172.104.55.33`
- AWS WAF: Add address `172.104.55.33/32` to block list
INTELLIGENCE JUDGMENT
The IP address 172.104.55.33 represents cloud infrastructure from Linode Singapore with moderate risk scoring driven by DNSBL listings. While no active threat indicators were identified, the DNSBL associations warrant traffic filtering. The neighborhood contains similarly scored IPs, suggesting this subnet may be underutilized or experiencing elevated baseline risk. Recommend monitoring for any escalation in threat indicators or abuse activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Linode |
| ASN | AS63949 |
| Network Name | LINODE |
| CIDR Block | 172.104.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 172-104-55-33.ip.linodeusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 172-104-55-33.ip.linodeusercontent.com |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.16 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 22% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-30 11:03:24 UTC |
| Last Seen | 2026-08-13 00:39:02 UTC |
| Profile Built | 2026-08-13 00:40:38 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 25 |
Full dossier details are available via our API.