# IP Intelligence Briefing: 172.234.103.136/32
## Executive Summary
IP 172.234.103.136 is a Linode-hosted infrastructure endpoint with low-risk classification (risk score: 25/100). The IP demonstrates no active malicious indicators, no open services, and minimal neighborhood threat density. No immediate defensive action recommended.
## Ownership and Network Classification
- Organization: Linode (ASN: 63949)
- CIDR Block: 172.232.0.0/13 (LINODE)
- Network Role: Classified as Tor Exit Nodes; however, isTor flag is FALSE
- Infrastructure Type: Unknown
- Service Status: No open ports detected; classified as "Firewalled / No Services"
- DNS Resolution: 172-234-103-136.ip.linodeusercontent.com (linodeusercontent.com)
## Geolocation
Multiple geolocation sources indicate conflicting data:
- US/Stockholm County (multiple sources)
- Sweden (maxmind-geolite2-city source)
- Latitude/Longitude: 39.83, -98.58 (low confidence: 0.35)
- Accuracy Radius: 2500km
- Consensus: TRUE (geoConsensus flag)
## Threat Indicators
- Risk Score: 25 (Low Risk)
- Abuse Confidence Score: null
- Blacklist Count: 0
- Threat Feeds: None detected
- Campaign Correlation: 0 matches
- Known Attacks: No evidence
- Spam Source: No
- Tor Exit Node: No (despite classification flag)
## Network Neighborhood Analysis
- Subnet: 172.234.103.136/24
- Abuse Density: 1 (extremely low)
- Classification: mostly_clean
- Inherited Risk: 2 (low)
- Active Siblings: 0
- Threat Siblings: 1 (out of 1 total sibling)
- Total Neighbors: 0
## Control Plane Assessment
- BGP Prefix: 172.234.96.0/19
- Route Stability: FALSE (isRouteStable)
- Route Changes (30d): 0
- DNSBL Listings: 1 of 8 total lists
- RPKI State: Not validated
- IRR Consistency: Not evaluated
## Temporal Analysis
- Observation Count: 1 threat observation
- Persistence Days: 0
- Ownership Changes: 0
- Persistently Malicious: FALSE
- Recent History: 20 observations over monitoring period showing consistent low-risk classification
## Relationship Graph
- DNS Associations: 172-234-103-136.ip.linodeusercontent.com
- Network Affiliations: LINODE network
## Security Recommendations
No firewall rules or mitigation actions recommended. The IP presents minimal threat:
- Risk score of 25 indicates low malicious probability
- No active services or open ports
- No blacklist entries or threat feed matches
- Low neighborhood abuse density
- No observed malicious campaign activity
## SOC Analyst Guidance
This IP should be permitted through standard security policies. Monitor for any changes in service status or threat indicators, particularly given the Tor Exit Node classification flag. The conflicting geolocation data warrants periodic verification if used in security rules that depend on geographic filtering. No immediate investigation required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Linode |
| ASN | AS63949 |
| Network Name | LINODE |
| CIDR Block | 172.232.0.0/13 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 172-234-103-136.ip.linodeusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 172-234-103-136.ip.linodeusercontent.com |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 17% | 1 | 1 |
| ownership | 35% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 24% | 2 | 2 |
| Overall | 26% | 9 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-06-07 10:15:47 UTC |
| Last Seen | 2026-06-21 13:49:07 UTC |
| Profile Built | 2026-06-21 13:51:32 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 22 |
Full dossier details are available via our API.