IP INTELLIGENCE BRIEFING: 172.233.155.45/32
Executive Summary:
This IP address belongs to Linode cloud infrastructure (ASN 63949) and presents a moderate risk score of 60/100. The address shows behavioral indicators of malicious activity including six honeypot interactions, though no active threat indicators were detected. Geolocation data contains significant validation anomalies requiring analyst review.
Ownership and Infrastructure:
- Provider: Linode (Infrastructure Cloud)
- ASN: 63949
- CIDR Block: 172.232.0.0/13
- Network Role: Cloud compute hosting environment
- Service Status: No open services detected; connection classified as "Firewalled / No Services"
Geolocation Analysis:
- Reported Location: United States, California, Los Angeles
- Validation Status: GEOLOCATION ANOMALY DETECTED
- Anomaly: RTT measurement (87ms) is physically inconsistent with claimed distance (9,014km). Minimum possible RTT for this distance is 180.3ms. This indicates unreliable or spoofed geolocation data.
- Confidence: Low confidence geolocation (0.35) with 2,500km accuracy radius
Threat Assessment:
- Risk Score: 60/100 (Moderate Risk)
- Threat Indicators: None currently active
- Blacklist Status: Listed on 1 of 8 DNSBLs
- Malicious Activity Flags:
- Honeypot Hits: 6 (significant behavioral indicator)
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Persistence: No persistent malicious activity detected; threat observation count: 0
Observation History:
Analysis of 16 historical observations reveals:
- Ownership remains stable with no changes
- Recent ASN/RIR confirmation validates Linode ownership
- No evidence of escalating threat behavior over time
- Geographic signals show low confidence with inconsistent country attribution
Relationships and Neighborhood:
- Related Entities: 2 relationships identified, both indicating membership in LINODE network
- Subnet Analysis: No neighboring IPs detected in /24 subnet
- Abuse Density: 0.0 (no abuse activity observed in adjacent addresses)
Recommended Actions:
- Primary: Increase logging verbosity and review recent activity from this IP address
- Firewall Rule: Consider blocking if internal policy prohibits cloud hosting providers with elevated risk scores
- Monitoring: Track for any changes in behavior, DNSBL listings, or threat indicator emergence
Analysis Notes:
The six honeypot hits represent the most concerning indicator, suggesting attempts to interact with security monitoring infrastructure. However, the absence of active threat indicators, combined with Linode's legitimate cloud infrastructure status, suggests this may represent either: (1) compromised customer systems, (2) misconfigured security tools, or (3) automated scanning activity. The geolocation validation failure indicates analysts should not rely on location-based context for decision-making.
Classification: Moderate Risk - Cloud Infrastructure with Behavioral Anomalies
Recommendation: Monitor with elevated logging; no immediate blocking required unless additional threat intelligence emerges.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
| Honeypot | Trap endpoint probes | 3 |
π’ Ownership & Registration
| Organization | Linode |
| ASN | AS63949 |
| Network Name | LINODE |
| CIDR Block | 172.232.0.0/13 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 172-233-155-45.ip.linodeusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 172-233-155-45.ip.linodeusercontent.com |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | AkamaiGHost |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 2 |
| routing | 17% | 1 | 1 |
| services | 35% | 2 | 3 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 27% | 10 | 14 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-08-03 13:10:06 UTC |
| Last Seen | 2026-08-13 05:07:43 UTC |
| Profile Built | 2026-08-13 05:22:53 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 27 |
Full dossier details are available via our API.