## IPDEBRIEF INTELLIGENCE BRIEFING
Target: 172.234.231.111/32
Classification: Cloud Infrastructure Host
Risk Assessment: Moderate Risk (Score: 40)
Report Date: June 16, 2026
---
EXECUTIVE SUMMARY
Target 172.234.231.111 is a Linode cloud computing host located in the US (Washington region). The IP exhibits moderate risk characteristics with no active threat indicators but maintains basic cloud hosting attributes. The subnet shows minimal abuse density, and the target is not associated with known malicious campaigns.
---
INFRASTRUCTURE PROFILE
| Attribute | Value |
|---|---|
| **Organization** | Linode (ASN 63949) |
| **Network Block** | 172.232.0.0/13 |
| **Geolocation** | United States, WA (Tukwila) |
| **Infrastructure Type** | CloudCompute |
| **Connection Type** | Single-Service Host |
| **Cloud Classification** | Cloud Hosting Environment |
---
THREAT INDICATORS
- Risk Score: 40 (Moderate)
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Blacklist Count: 0
- DNSBL Listings: 2 of 8 total lists
- Abuse Confidence: Not scored
- Known Campaigns: None identified
- Persistent Malicious Activity: No
---
NETWORK SERVICES
Open Ports:
- TCP/22 (SSH) - SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15
DNS Analysis:
- PTR Record: 172-234-231-111.ip.linodeusercontent.com
- Forward Resolution: Confirmed
- SPF Records: None
- DMARC Records: None
- Hosted Domains: 0
---
SUBNET NEIGHBORHOOD ASSESSMENT
Subnet: 172.234.231.0/24
- Abuse Density: 0 (Clean classification)
- Total Siblings: 2
- Active Siblings: 1
- Threat Siblings: 0
Neighbor Profile:
- 172.234.231.96: Risk Score 25, Authority Score 60
---
OBSERVATION HISTORY
Eighteen signal observations recorded since analysis began. Key historical signals include:
- Recent port scans identifying SSH service
- Subnet classification consistently marked as "clean"
- No ownership changes detected
- No threat persistence indicators
No evidence of evolving risk posture over the observation period.
---
RELATIONSHIP GRAPH
Nine relationships identified:
- Multiple same-network associations to LINODE network
- DNS associations to 172-234-231-111.ip.linodeusercontent.com
- No external organizational or certificate-based relationships detected
---
RECOMMENDED ACTIONS
Risk Score: 40 - Moderate Risk
Suggested Firewall Rules:
- iptables: `iptables -A INPUT -s 172.234.231.111 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 172.234.231.111 drop`
- nginx: `deny 172.234.231.111;`
- pfSense: `172.234.231.111/32`
Additional Recommendations:
- No specific recommendations generated due to moderate risk profile
- Consider monitoring for SSH-based attacks given open port 22
- Review DNSBL listings for potential reputation concerns
- Validate against internal threat intelligence before implementing block rules
---
ANALYST NOTES
This IP represents a standard cloud hosting environment with typical Linode infrastructure characteristics. The moderate risk score stems primarily from basic hosting classification and DNSBL listings rather than active malicious behavior. No immediate threat indicators require escalation. SOC teams should weigh the risk score against operational requirements before implementing blocking measures, particularly given the clean subnet neighborhood and lack of active threat indicators.
Classification: Defensive Intelligence
Data Source: IPDebrief Automated Analysis
Disclaimer: Recommendations are probabilistic and should be combined with additional signals before action.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Linode |
| ASN | AS63949 |
| Network Name | LINODE |
| CIDR Block | 172.232.0.0/13 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 172-234-231-111.ip.linodeusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 172-234-231-111.ip.linodeusercontent.com |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 2 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 24% | 2 | 2 |
| Overall | 23% | 10 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-06-07 19:58:26 UTC |
| Last Seen | 2026-06-21 14:09:25 UTC |
| Profile Built | 2026-06-21 14:11:48 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 22 |
Full dossier details are available via our API.