# IP Intelligence Briefing: 172.105.23.240
Classification: Moderate Risk (Score: 50) | Infrastructure: Cloud Compute (Linode) | Country: Canada (Toronto, ON)
---
## Executive Summary
IP 172.105.23.240 is a Linode cloud infrastructure address with moderate risk scoring primarily attributed to DNSBL listings. The IP resolves to binaryedge.ninja infrastructure and shows no active threat indicators, known campaigns, or malicious activity patterns.
---
## Infrastructure Profile
- Provider: Linode (ASN 63949)
- Network: 172.104.0.0/16
- Geolocation: Toronto, Ontario, Canada
- Infrastructure Type: CloudCompute / Cloud Hosting
- Service Status: Firewalled / No Services Open
---
## Threat Assessment
Risk Score: 50 (Moderate)
Threat Indicators:
- No known attack campaigns
- No identified attacker profiles
- No spam source classification
- No Tor exit node activity
Reputation Sources: DNSBL listed on 2 of 8 total blacklists
---
## Network Context & Neighborhood Analysis
Subnet Classification: Clean (172.105.23.0/24)
- Abuse Density: 0
- Active Siblings: 5 of 6 total
- Threat Siblings: 0
Neighbor Risk Distribution:
- High Risk: 0
- Medium Risk: 0
- Low Risk: 5 (Risk scores: 20-25)
The /24 subnet demonstrates clean characteristics with no associated threat activity.
---
## Observations & History
- Total Signals: 18 observations recorded
- Threat Persistence: 0 days (no persistent malicious behavior)
- Ownership Changes: 0
- Recent Activity: Multiple geolocation and traceroute observations from 2026-07-31 indicating network routing through Comcast infrastructure
---
## DNS Intelligence
- PTR Record: prod-fluorine-ca-central-3.li.binaryedge.ninja
- Forward Resolution: Confirmed to binaryedge.ninja domain
- Forward Hostnames: 1 (prod-fluorine-ca-central-3.li.binaryedge.ninja)
- DNSSEC: Valid
- Email Auth: SPF enabled, DMARC not configured
---
## Recommended Actions
Current Status: Monitor but no immediate blocking recommended.
Suggested Firewall Rules:
- No blocking required; IP operates within legitimate cloud infrastructure parameters
- Monitor for changes in DNSBL status or emergence of threat indicators
- Review binaryedge.ninja service legitimacy if unfamiliar with the infrastructure
---
Conclusion: This IP represents legitimate cloud infrastructure hosting. The moderate risk score derives from DNSBL presence rather than observed malicious behavior. No immediate threat mitigation actions required. Continue monitoring for changes in reputation or threat indicators.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Linode |
| ASN | AS63949 |
| Network Name | LINODE |
| CIDR Block | 172.104.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | prod-fluorine-ca-central-3.li.binaryedge.ninja |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | prod-fluorine-ca-central-3.li.binaryedge.ninja |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.16 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 43% | 2 | 5 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 30% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 4 |
| Overall | 27% | 10 | 18 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-30 17:11:35 UTC |
| Last Seen | 2026-08-13 00:52:42 UTC |
| Profile Built | 2026-08-13 01:07:20 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 24 |
Full dossier details are available via our API.