# IPDebrief Intelligence Briefing
Target: 172.110.223.231/32
Classification: Low Risk
Report Date: 2026-07-30
---
## Executive Summary
The target IP address 172.110.223.231 exhibits a low risk profile with a risk score of 0. No threat indicators, blacklisting, or active malicious behavior have been observed. The IP is geographically registered to Hong Kong but geolocated to New York, with no open services or network traffic signatures detected. The subnet shows moderate neighbor risk distribution, though the target itself remains unflagged.
---
## Risk Assessment
| Metric | Value |
|---|---|
| Risk Score | 0 |
| Provider Score | 0 |
| Authority Score | 0 |
| Stability Score | 0 |
| Reputation | Low Risk |
| Abuse Confidence Score | N/A |
Threat Indicators:
- Tor exit node: No
- Known attacker: No
- Spam source: No
- Blacklist count: 0
- Threat feeds: None
---
## Ownership & Registration
- Organization: Abuse contact role object (dedires)
- CIDR Block: 172.110.223.0/24
- Registry: ARIN
- ASN: N/A
- Registration Date: N/A
- Abuse Contact: Available via RDAP
---
## Geolocation
- Country: Hong Kong (HK)
- Region: US-NY
- City: New York
- Coordinates: 22.4°N, 114.11°E
- Timezone: Asia/Hong_Kong
- Accuracy Radius: 30km
- Geo Consensus: True
- Geo Plausible: False (discrepancy noted)
---
## Network Services & DNS
| Category | Status |
|---|---|
| Open Ports | None detected |
| TLS Certificate | N/A |
| Hosted Domains | 0 |
| DNSSEC Valid | Yes |
| PTR Records | None |
| Forward Resolution | No |
| Email Auth (SPF/DMARC) | Not configured |
Network Role: Firewalled / No Services
Classification: Not cloud, CDN, VPN, proxy, Tor, hosting, mobile, residential, bogon, or anycast
---
## Neighborhood Analysis
Subnet: 172.110.223.0/24
Total Siblings: 23
Abuse Density: 0
Risk Distribution:
- High Risk: 0
- Medium Risk: 7
- Low Risk: 15
Notable Neighbors (Risk Score โฅ 25):
- 172.110.223.59 (25)
- 172.110.223.72 (25)
- 172.110.223.114 (40)
- 172.110.223.147 (25)
- 172.110.223.151 (25)
- 172.110.223.157 (40)
- 172.110.223.161 (25)
- 172.110.223.164 (40)
- 172.110.223.177 (25)
- 172.110.223.179 (40)
- 172.110.223.195 (25)
- 172.110.223.199 (40)
- 172.110.223.201 (25)
- 172.110.223.203 (40)
- 172.110.223.216 (40)
- 172.110.223.224 (30)
The subnet exhibits moderate risk concentration among neighbors, with no high-risk activity directly associated with the target.
---
## Historical Signal Analysis
Total Observations: 12
Recent Activity: 2026-07-30
Key historical signals include:
- Geolocation updates (HK region)
- DNSSEC validation confirmed
- ASN data from team-cymru-dns registry
- No ownership changes recorded
- No threat persistence observed
- No persistent malicious behavior
---
## Relationships
Connected Entities: 3
Relationship Type: Same Network (dedires)
No external relationships detected with hostnames, organizations, or certificates beyond the network association.
---
## Control Plane
| Metric | Value |
|---|---|
| Origin ASN | N/A |
| BGP Prefix | N/A |
| Route Stable | No |
| RPKI State | N/A |
| DNSSEC Valid | Yes |
| DNSBL Listed | 0 |
| Transit Networks | Comcast |
| Hop Count | 11 |
---
## Recommended Security Actions
No specific firewall rules or mitigation actions are recommended at this time. The IP demonstrates no active threat characteristics.
Suggested Monitoring:
- Maintain passive observation of the subnet (172.110.223.0/24)
- Monitor medium-risk neighbors for escalation
- Periodic re-scanning recommended due to subnet's moderate risk profile
---
## Conclusion
IP 172.110.223.231 is classified as Low Risk with no actionable threat indicators. The subnet context warrants continued monitoring given 7 medium-risk neighbors, but the target IP itself shows no signs of malicious activity, blacklisting, or network exploitation. Standard network hygiene monitoring is appropriate.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Abuse contact role object |
| ASN | โ |
| Network Name | dedires |
| CIDR Block | 172.110.223.0/24 |
| RIR | ARIN |
| Country | HK |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_7.4 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 4% | 1 | 2 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-25 21:00:27 UTC |
| Last Seen | 2026-08-01 04:25:14 UTC |
| Profile Built | 2026-07-30 05:27:03 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 16 |
Full dossier details are available via our API.