IP Intelligence Briefing: 172.105.39.145
Date: 2026-06-13
---
**1. Core Profile**
- Risk Score: 25 (Low Risk)
- Provider: Linode (AS63949)
- Geolocation: US-NY (New York), inferred via Linode's infrastructure.
- Network Role: CloudCompute (Linode VM/hosting).
- Threat Indicators: No active malware, phishing, or exploitation indicators.
- DNS: Resolves to `172-105-39-145.ip.linodeusercontent.com` (Linode CDN).
- Services: No open ports or TLS services detected.
---
**2. Observation History**
- Recent Activity:
- Last observed June 13, 2026, with consistent cloud infrastructure attributes.
- DNSBL Listing: Identified in 1 of 8 threat feeds (low-severity).
- BGP Stability: Route stability score indicates no recent network disruptions.
- Trend: No significant changes in risk or network behavior over the past 30 days.
---
**3. Relationships**
- Network: Linked to Linode's "LINODE" ASN (AS63949).
- DNS: Associated with `linodeusercontent.com` (CDN infrastructure).
- No Known Campaigns: No correlation with known malicious campaigns or compromised hosts.
---
**4. Neighborhood Analysis**
- Subnet: 172.105.39.0/24 (Linode network).
- Neighbor Risk:
- 1 active IP in subnet (172.105.39.172) with authority score 60 (moderate risk).
- Subnet abuse density: 0% (low risk).
---
**5. Recommendations**
- Monitor DNS: Track `linodeusercontent.com` for unusual traffic patterns.
- Check DNSBL Context: Investigate the 1/8 DNSBL listing to confirm legitimacy (e.g., false positives).
- Subnet Surveillance: Focus on 172.105.39.172 due to higher authority score, though no direct threat detected.
- Cloud Provider Alerting: Collaborate with Linode to verify account security if suspicious activity arises.
---
Conclusion:
This IP is a low-risk cloud instance associated with Linode. While no direct threats are detected, the DNSBL listing and subnet neighbor activity suggest cautious monitoring. No immediate mitigation required, but ongoing observation is advised.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Linode |
| ASN | AS63949 |
| Network Name | LINODE |
| CIDR Block | 172.104.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 172-105-39-145.ip.linodeusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 172-105-39-145.ip.linodeusercontent.com |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | nginx/1.24.0 (Ubuntu) |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
π TLS Certificate
| SANs | aqarize.com |
| Valid From | 2026-05-28T14:44:23+00:00 |
| Valid Until | 2026-08-26T14:44:22+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
| Serial Number | 057CB03B09126CC28CCF4DF488FC5C3E0235 |
| Thumbprint | 375546425D8D85395CC3CDD2BE854FA0CF0AEE17 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 32% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 13% | 1 | 1 |
| ownership | 30% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 37% | 2 | 3 |
| Overall | 25% | 9 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Fresh
| First Seen | 2026-06-05 07:04:52 UTC |
| Last Seen | 2026-06-21 12:07:31 UTC |
| Profile Built | 2026-06-21 15:30:48 UTC |
| Data Freshness | Fresh |
| Signal Types | 23 |
| Total Observations | 25 |
Full dossier details are available via our API.