IPDebrief

172.234.192.95

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 172.234.192.95/32

## Executive Summary

IP address 172.234.192.95 was identified as a low-risk infrastructure endpoint belonging to Linode cloud computing infrastructure. The IP presented no threat indicators, blacklist associations, or malicious activity markers during observation.

## Infrastructure Profile

The IP resolved to Linode (ASN 63949) cloud infrastructure within the 172.232.0.0/13 CIDR block. Ownership was attributed to the LINODE organization, with abuse contact available via RDAP. The IP registered to the ARIN registry and operated from the United States (US-NY/New York region) according to geolocation consensus. DNS resolution confirmed the hostname 172-234-192-95.ip.linodeusercontent.com with forward resolution validated.

## Threat Assessment

Risk scoring returned a baseline of zero across all categories: reputation (0), provider score (0), authority score (0), and stability score (0). No threat indicators were detected in the threat database. The IP was not flagged as a Tor exit node, known attacker, or spam source. Blacklist enumeration returned zero matches across monitored threat feeds. No malicious campaigns correlated with this address.

## Network Observations

Port scanning revealed no open services on the target. The IP maintained a cloud computing role with infrastructure classification marked as isCloud: true and isHosting: true. Traceroute analysis traced the path through 20 hops with first hop RTT of 0.2ms and final hop RTT of 35.3ms, with 4 timeouts recorded in transit networks including Comcast.

## Historical Context

Sixteen signal observations were recorded, with recent activity documented on 2026-08-06. Geolocation signals showed consensus data from New York, US-NY, though occasional Chicago detections appeared in the signal stream. ASN and organization lookups consistently confirmed Linode ownership. Traceroute validation confirmed successful target reachability.

## Geographic Consistency

Geolocation validation showed geoPlausible: false, with distance and RTT metrics unpopulated. Multiple geolocation sources provided varying city-level data (New York, Chicago), which is consistent with cloud provider IP allocation patterns where geolocation accuracy may be limited.

## Neighborhood Analysis

The /24 subnet (172.234.192.95/24) returned zero neighbor IPs in the sibling enumeration. Abuse density for the subnet was calculated at 0. Risk distribution across the neighborhood showed no high, medium, or low risk classifications. No threat siblings were identified in the immediate subnet.

## Related Entities

Three relationship associations were identified: two DNS associations to the hostname 172-234-192-95.ip.linodeusercontent.com, and one same-network association to LINODE. No organizational links, certificate matches, or correlated IPs were found.

## Control Plane Data

The control plane assessment showed origin ASN 63949 with BGP prefix 172.234.192.0/19. Route stability was flagged as false. RPKI state, IRR consistency, and route changes within 30 days were not populated. DNSSEC validation returned true. DNSBL listing count was zero across 8 total lists.

## Operational Classification

The IP was classified as a cloud computing endpoint with service purpose marked as "Firewalled / No Services." It was not identified as CDN, VPN, proxy, Tor, hosting, mobile, residential, bogon, or anycast infrastructure.

## Recommendation

No security actions were recommended by the analysis engine. The IP presents as legitimate cloud infrastructure with no observable threat characteristics. SOC teams may treat this as a benign infrastructure IP without additional monitoring requirements beyond standard baseline traffic analysis.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionIllinois
CityChicago
Timezoneβ€”
Latitude41.85
Longitude-87.65

🏒 Ownership & Registration

OrganizationLinode
ASNAS63949
Network NameLINODE
CIDR Block172.232.0.0/13
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR172-234-192-95.ip.linodeusercontent.com
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnames172-234-192-95.ip.linodeusercontent.com

πŸ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierTier 3 β€” Basic operator with some routing infrastructure
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
35%
23
routing
17%
11
services
24%
22
ownership
35%
23
reputation
17%
12
geolocation
35%
23
Overall27%1014
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) β€” 1 contradiction(s)
AttributionModerate (55%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Claimed geolocation contradicts RTT physics measurement

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-07-31 05:27:58 UTC
Last Seen2026-08-13 01:20:50 UTC
Profile Built2026-08-13 01:34:09 UTC
Data FreshnessLive
Signal Types22
Total Observations23
πŸ” 22 signal types Β· 23 observations collected
This report is generated from 22+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.