# IP Intelligence Briefing: 172.234.192.95/32
## Executive Summary
IP address 172.234.192.95 was identified as a low-risk infrastructure endpoint belonging to Linode cloud computing infrastructure. The IP presented no threat indicators, blacklist associations, or malicious activity markers during observation.
## Infrastructure Profile
The IP resolved to Linode (ASN 63949) cloud infrastructure within the 172.232.0.0/13 CIDR block. Ownership was attributed to the LINODE organization, with abuse contact available via RDAP. The IP registered to the ARIN registry and operated from the United States (US-NY/New York region) according to geolocation consensus. DNS resolution confirmed the hostname 172-234-192-95.ip.linodeusercontent.com with forward resolution validated.
## Threat Assessment
Risk scoring returned a baseline of zero across all categories: reputation (0), provider score (0), authority score (0), and stability score (0). No threat indicators were detected in the threat database. The IP was not flagged as a Tor exit node, known attacker, or spam source. Blacklist enumeration returned zero matches across monitored threat feeds. No malicious campaigns correlated with this address.
## Network Observations
Port scanning revealed no open services on the target. The IP maintained a cloud computing role with infrastructure classification marked as isCloud: true and isHosting: true. Traceroute analysis traced the path through 20 hops with first hop RTT of 0.2ms and final hop RTT of 35.3ms, with 4 timeouts recorded in transit networks including Comcast.
## Historical Context
Sixteen signal observations were recorded, with recent activity documented on 2026-08-06. Geolocation signals showed consensus data from New York, US-NY, though occasional Chicago detections appeared in the signal stream. ASN and organization lookups consistently confirmed Linode ownership. Traceroute validation confirmed successful target reachability.
## Geographic Consistency
Geolocation validation showed geoPlausible: false, with distance and RTT metrics unpopulated. Multiple geolocation sources provided varying city-level data (New York, Chicago), which is consistent with cloud provider IP allocation patterns where geolocation accuracy may be limited.
## Neighborhood Analysis
The /24 subnet (172.234.192.95/24) returned zero neighbor IPs in the sibling enumeration. Abuse density for the subnet was calculated at 0. Risk distribution across the neighborhood showed no high, medium, or low risk classifications. No threat siblings were identified in the immediate subnet.
## Related Entities
Three relationship associations were identified: two DNS associations to the hostname 172-234-192-95.ip.linodeusercontent.com, and one same-network association to LINODE. No organizational links, certificate matches, or correlated IPs were found.
## Control Plane Data
The control plane assessment showed origin ASN 63949 with BGP prefix 172.234.192.0/19. Route stability was flagged as false. RPKI state, IRR consistency, and route changes within 30 days were not populated. DNSSEC validation returned true. DNSBL listing count was zero across 8 total lists.
## Operational Classification
The IP was classified as a cloud computing endpoint with service purpose marked as "Firewalled / No Services." It was not identified as CDN, VPN, proxy, Tor, hosting, mobile, residential, bogon, or anycast infrastructure.
## Recommendation
No security actions were recommended by the analysis engine. The IP presents as legitimate cloud infrastructure with no observable threat characteristics. SOC teams may treat this as a benign infrastructure IP without additional monitoring requirements beyond standard baseline traffic analysis.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Linode |
| ASN | AS63949 |
| Network Name | LINODE |
| CIDR Block | 172.232.0.0/13 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 172-234-192-95.ip.linodeusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 172-234-192-95.ip.linodeusercontent.com |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 27% | 10 | 14 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-31 05:27:58 UTC |
| Last Seen | 2026-08-13 01:20:50 UTC |
| Profile Built | 2026-08-13 01:34:09 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 23 |
Full dossier details are available via our API.