Threat Intelligence Briefing: IP 172.191.94.172/32
Date: [Insert Date of Analysis]
Subject: IP Address 172.191.94.172/32
Summary:
The IP address 172.191.94.172/32 was analyzed to determine its threat potential, history, and network environment. This private IP address falls within the Class B private range (172.16.0.0 to 172.31.255.255), typically used for internal networks in organizations. As such, it is not routable on the public internet.
Observation History:
- Activity Logs: There were no direct records of activity on this IP address in public threat intelligence databases, reflecting its classification as a private IP.
- Incident Reports: No incidents or security breaches were associated with this IP in available public or private threat intelligence feeds.
Relationships:
- Organizational Use: Likely associated with internal services or devices within an organization, as it falls within the private IP range.
- Known Hosts: No external hostnames or domains were publicly associated with this IP address.
Neighborhood Data:
- Subnet Analysis: The subnet 172.191.94.0/24 is a private range, indicating the IP is part of an internal network infrastructure.
- Network Traffic Patterns: No external traffic patterns or anomalies were observed in public datasets.
Threat Potential:
- Risk Level: Low, given the private nature of the IP and lack of public activity or threat associations.
- Mitigation Recommendations: Internal monitoring and network security measures should be maintained to ensure the integrity and security of internal systems.
Conclusion:
IP 172.191.94.172/32 is a private IP address with no recorded public activity or threat associations. It is likely used internally within an organization. SOC analysts should focus on internal network security measures to monitor and protect this IP address from potential internal threats or misconfigurations.
Actionable Steps:
1. Internal Monitoring: Ensure robust logging and monitoring of internal network traffic involving this IP.
2. Access Controls: Review and enforce access controls to limit unauthorized access to devices using this IP.
3. Security Policies: Regularly update security policies to address potential vulnerabilities within the internal network.
This briefing is based on available public and private threat intelligence data as of [Insert Date of Analysis]. For further internal investigation, collaboration with the organization's internal IT and security teams is recommended.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Divya Quamara |
| ASN | AS8075 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Multi-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 443, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | nginx/1.18.0 (Ubuntu) |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 42% | 2 | 5 |
| routing | 8% | 1 | 1 |
| services | 26% | 2 | 4 |
| ownership | 20% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 25% | 10 | 19 |
| Data Coherence | Mixed Signals (60%) โ 2 contradiction(s) |
| Attribution | Very Low (20%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
โ Geo sources disagree on country: US, GB
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-08 05:01:49 UTC |
| Last Seen | 2026-06-27 12:30:26 UTC |
| Profile Built | 2026-06-28 06:34:12 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 30 |
Full dossier details are available via our API.