## IP INTELLIGENCE BRIEFING: 172.235.181.217/32
Classification: Moderate Risk (Score: 65)
Report Date: Current
Analyst: IPDebrief Intelligence Team
---
Executive Summary
Target IP 172.235.181.217 is a Linode cloud compute infrastructure host with moderate risk characteristics. The address resolves to a hostname associated with "academyforinternetresearch.org" and exhibits standard cloud provider patterns. No active malicious campaigns detected. Risk factors include DNSBL listings and moderate reputation score.
---
Technical Profile
- IP Address: 172.235.181.217/32
- ASN: AS63949 (Linode)
- Organization: Linode
- Infrastructure Type: Cloud Compute (Cloud Provider: Yes)
- Location: US (North Holland, Amsterdam)
- Risk Score: 65/100 (Moderate Risk)
- Abuse Confidence Score: Not Available
Network Characteristics
- Provider Score: 0
- Authority Score: 0
- Stability Score: 0
- BGP Prefix: 172.235.160.0/19
- Route Stability: False
- DNSBL Status: Listed on 3 of 8 total lists
DNS Resolution
- PTR Hostname: prod47client01.academyforinternetresearch.org
- Forward Resolution: Confirmed (1 hostname)
- Email Authentication: SPF configured; DMARC not present
Service Exposure
- Open Port 22 (TCP): SSH (OpenSSH_8.9p1 Ubuntu-3ubuntu0.15)
- TLS Certificate: None detected
- HTTP Service: None detected
---
Historical Observations
Total Signal Observations: 24
| Date | Signal Type | Operator Score | Confidence |
|---|---|---|---|
| 2026-06-19 | Basic Routing | 0.3478 | 60% |
| 2026-06-17 | Basic Routing | 0.3478 | 60% |
| 2026-06-14 | Geolocation | N/A | 35% |
Temporal Analysis: No persistent malicious activity detected. Ownership changes: 0. Threat observation count: 1. Last activity observed June 19, 2026.
---
Relationship Graph
Total Relationships: 43
Key Associations:
- DNS: prod47client01.academyforinternetresearch.org (multiple entries)
- Network: LINODE (same network)
- Infrastructure: Cloud compute environment
---
Neighborhood Analysis
Subnet: 172.235.181.217/24
- Abuse Density: 0 (mostly_clean)
- Total Siblings: 2
- Active Siblings: 2
- Threat Siblings: 2
- Inherited Risk: 5
Neighbor Profile:
| IP | Risk Score | Authority Score |
|---|---|---|
| 172.235.181.226 | 40 | 60 |
---
Threat Indicators
- Campaign Likelihood: None
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Blacklist Count: 0
- Threat Feeds: None detected
---
Recommended Actions
Based on risk profile assessment:
Priority 1 - Monitoring:
- Monitor outbound traffic patterns from this IP
- Track SSH connection attempts (port 22)
Priority 2 - Policy Review:
- Evaluate connection rules for 172.235.181.0/24 subnet
- Review DNSBL listing implications for email filtering
Priority 3 - Intelligence:
- Investigate "academyforinternetresearch.org" domain for additional context
- Correlate with any observed malicious activity from related IPs
---
Intelligence Assessment
This IP represents a legitimate cloud infrastructure host with moderate risk due to DNSBL listings and lack of DMARC configuration. The association with an "academy" domain requires contextual investigation. No active threat campaigns or persistent malicious behavior observed. Recommend standard monitoring with awareness of cloud provider infrastructure patterns.
Threat Level: MODERATE
Action Required: Standard monitoring and policy review
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Linode |
| ASN | AS63949 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | prod47client01.academyforinternetresearch.org |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | prod47client01.academyforinternetresearch.org |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 21% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:03:54 UTC |
| Last Seen | 2026-06-27 02:06:05 UTC |
| Profile Built | 2026-06-27 20:12:03 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 27 |
Full dossier details are available via our API.