IPDebrief

172.104.55.33

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

IPDEBRIEF INTELLIGENCE BRIEFING

Target: 172.104.55.33/32

Classification: Cloud Infrastructure IP – Moderate Risk

---

PROFILING SUMMARY

The target IP address 172.104.55.33 belongs to Linode (AS63949), a cloud hosting provider operating from Singapore. The IP is classified as cloud compute infrastructure with a risk score of 50 (Moderate Risk). DNS resolution confirmed the address resolves to 172-104-55-33.ip.linodeusercontent.com with forward confirmation verified. No open ports or active services were detected on the target.

OWNERSHIP & INFRASTRUCTURE

AttributeValue
ASN63949 (Linode)
OrganizationLINODE
CIDR Block172.104.0.0/16
GeolocationSingapore (SG)
Infrastructure TypeCloudCompute
DNSBL Listings8 total (2 high severity)

THREAT ASSESSMENT

The IP maintains a moderate risk profile with no active threat indicators detected. The address is not classified as a Tor exit node, known attacker, or spam source. The control plane indicates the IP is listed on 8 DNSBLs, with 2 listings flagged as high severity. No known malware campaigns correlate with this address.

NEIGHBORHOOD ANALYSIS

The /24 subnet (172.104.55.0/24) contains 2 active sibling IPs with an abuse density of 0. One neighboring IP (172.104.55.192) also carries a risk score of 50 with an authority score of 60. The subnet is classified as clean with no inherited threat risk.

OBSERVATION HISTORY

Historical analysis returned 23 observations. Key temporal signals indicate subnet abuse density fluctuated between 0 and 0.5 during the observation window. Routing stability remains inconsistent, with route changes recorded within the 30-day period. Geolocation data consistently validated Singapore location with RTT measurements between 246-260ms.

RELATIONSHIP MAPPING

The IP exhibits 18 relationships, primarily DNS associations to the Linode hostname and network associations to the LINODE organization. No unique certificate subjects or correlated external IPs were identified in the relationship graph.

RECOMMENDED ACTIONS

Based on the moderate risk profile, the following actions are recommended:

INTELLIGENCE JUDGMENT

The IP address 172.104.55.33 represents cloud infrastructure from Linode Singapore with moderate risk scoring driven by DNSBL listings. While no active threat indicators were identified, the DNSBL associations warrant traffic filtering. The neighborhood contains similarly scored IPs, suggesting this subnet may be underutilized or experiencing elevated baseline risk. Recommend monitoring for any escalation in threat indicators or abuse activity.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΈπŸ‡¬ Singapore
Regionβ€”
CitySingapore
Timezoneβ€”
Latitude1.29
Longitude103.85

🏒 Ownership & Registration

OrganizationLinode
ASNAS63949
Network NameLINODE
CIDR Block172.104.0.0/16
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR172-104-55-33.ip.linodeusercontent.com
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnames172-104-55-33.ip.linodeusercontent.com

πŸ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierTier 3 β€” Basic operator with some routing infrastructure
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”
SSH VersionSSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.16

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
30%
23
routing
13%
11
services
19%
22
ownership
27%
23
reputation
17%
12
geolocation
27%
23
Overall22%1014
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-07-30 11:03:24 UTC
Last Seen2026-08-13 00:39:02 UTC
Profile Built2026-08-13 00:40:38 UTC
Data FreshnessLive
Signal Types23
Total Observations25
πŸ” 23 signal types Β· 25 observations collected
This report is generated from 23+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.