IP Intelligence Briefing: 172.235.192.35
Date: June 7, 2026
---
**1. Core Profile**
- Risk Score: Moderate (60/100)
- Provider: Linode (Cloud Hosting)
- Geolocation:
- Country: United States (US)
- Region: Osaka (possibly misattributed; verify)
- Coordinates: Latitude 39.83, Longitude -98.58 (approx. central US)
- Network Role: CloudCompute (Virtual Machine/Server)
- Services:
- Open ports: 443 (HTTPS), 22 (SSH), 8080 (HTTP-alt), 3389 (RDP)
- No TLS certificate detected
- No email security records (SPF/DKIM)
---
**2. Threat & Security Indicators**
- Threat Risk: Low
- No known malicious indicators (no malware, phishing, or exploit activity)
- DNSBL (DNS-based Blacklist) listing detected (1/8 total)
- Configuration Weaknesses:
- Missing DNSSEC validation
- No HTTP security headers (HSTS, CSP)
- SSH banner indicates OpenSSH 7.6p1 (patched, but no additional context)
---
**3. Network & Subnet Analysis**
- Subnet: 172.235.192.0/24 (Linode-managed)
- Neighbor Risk:
- Abuse Density: 0 (no malicious neighbors detected)
- Subnet Activity: No sibling IPs reported (may indicate sparse usage or data limitations)
- Routing:
- BGP ASN: 63949 (Linode)
- Route stability: Stable (no recent changes)
---
**4. Historical Observations**
- First Seen: May 31, 2026
- Consistency:
- Stable network role (CloudCompute)
- Geolocation data inconsistent (Osaka vs. US)
- No persistent malicious behavior (threat persistence: 0 days)
---
**5. Recommendations**
- Monitor:
- Open ports (SSH, RDP) for unauthorized access attempts.
- SSL/TLS configuration for 443 (HTTPS) to ensure encryption.
- Verify:
- Geolocation accuracy (Osaka, Japan vs. US). Potential misattribution.
- DNSSEC and email security records (SPF/DKIM) for domain validation.
- Action:
- Consider restricting non-essential ports (e.g., 8080, 3389) if not required.
- Validate Linode IP ownership to ensure no unauthorized use.
---
Conclusion:
This IP is associated with a Linode cloud server with moderate risk due to configuration gaps and inconsistent geolocation data. No direct malicious activity detected, but security best practices (e.g., TLS, DNSSEC) should be implemented to mitigate potential exploitation vectors. Monitor for anomalies in network behavior or new threat indicators.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
| Honeypot | Trap endpoint probes | 1 |
π’ Ownership & Registration
| Organization | Linode |
| ASN | AS63949 |
| Network Name | β |
| CIDR Block | 172.235.192.0/19 |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 172-235-192-35.ip.linodeusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 172-235-192-35.ip.linodeusercontent.com |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | β |
| 22 | ssh | tcp | |
| 8080 | http-alt | tcp | β |
| 3389 | rdp | tcp | β |
| Closed Ports | 25, 80, 8443 (4 open / 7 scanned) | ||
| Server | nginx |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_7.6p1 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 20% | 2 | 4 |
| routing | 22% | 3 | 4 |
| services | 26% | 2 | 3 |
| ownership | 22% | 3 | 4 |
| reputation | 24% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 24% | 13 | 21 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-14 12:37:58 UTC |
| Last Seen | 2026-06-28 00:36:44 UTC |
| Profile Built | 2026-06-28 18:41:43 UTC |
| Data Freshness | Live |
| Signal Types | 34 |
| Total Observations | 38 |
Full dossier details are available via our API.