# IP Intelligence Briefing: 172.233.80.237
## Executive Summary
IP address 172.233.80.237 is a Linode cloud compute infrastructure host classified as Low Risk (Risk Score: 25). The asset demonstrates stable operational characteristics with no persistent malicious activity detected across 21 observation cycles. No immediate security actions are recommended based on current threat intelligence.
## Ownership and Infrastructure
Provider: Linode (ASN: 63949)
Infrastructure Type: CloudCompute / Hosting
Network Role: Single-Service Host
CIDR Block: 172.233.64.0/19 (BGP Prefix)
The IP operates within Linode's cloud infrastructure and forwards to linodeusercontent.com. PTR hostname resolves to 172-233-80-237.ip.linodeusercontent.com with forward confirmation enabled. DNSSEC is valid; no CAA records present.
## Geolocation
Country: United States (US)
Region/City: Osaka
Accuracy Radius: 2,500 km
Validation: GeoPlausible = true (2 sources, consensus achieved)
*Note: Osaka location appears inconsistent with US geolocation; may indicate routing anomaly or data source discrepancy.*
## Threat Intelligence
Overall Risk Score: 25 (Low Risk)
Abuse Confidence: Not applicable
Blacklist Status: 0 entries
Known Attacker: No
Tor Exit Node: No
Spam Source: No
Threat Indicators: None detected
Campaign Likelihood: None
Cert Matches: 0
Correlated IPs: 0
## Network Services
Open Ports:
- Port 22/SSH (TCP) β OpenSSH_9.2p1 Debian-2+deb12u10
No TLS certificates or HTTP services detected.
## Neighborhood Analysis (172.233.80.0/24)
Abuse Density: 0 (Clean)
Threat Siblings: 0
Active Siblings: 1
Classification: Clean
No neighboring IPs flagged as malicious. Subnet exhibits minimal abuse activity.
## Control Plane
Operator Score: 0.2609 (Basic)
Route Stability: Not stable
DNSBL Listed: 1 of 8 total lists
RPKI State: Not evaluated
IRR Consistency: Not evaluated
## Historical Observation Summary
Total observations: 21
Recent activity (2026-06-19) shows:
- Subnet classification: Clean
- Inherited risk: 0
- Abuse density: 0
Historical geolocation signals include observations from 2026-06-14 referencing Akamai International (AS20940), indicating potential routing diversity or CDN integration.
## Recommended Actions
No immediate firewall or blocking actions required. The IP maintains a legitimate cloud hosting profile with no evidence of malicious activity. Standard cloud infrastructure monitoring protocols apply.
---
*Intelligence compiled from IPDebrief threat intelligence platform. Data reflects current operational state as of 2026-06-19.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Linode |
| ASN | AS63949 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 172-233-80-237.ip.linodeusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 172-233-80-237.ip.linodeusercontent.com |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.2p1 Debian-2+deb12u10 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 22% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 28% | 2 | 3 |
| ownership | 17% | 2 | 3 |
| reputation | 24% | 1 | 3 |
| geolocation | 31% | 2 | 3 |
| Overall | 22% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-13 06:37:25 UTC |
| Last Seen | 2026-06-27 22:43:51 UTC |
| Profile Built | 2026-06-28 22:49:29 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 27 |
Full dossier details are available via our API.