# IP Intelligence Briefing: 172.236.117.71/32
## Executive Summary
IP 172.236.117.71 is a Linode cloud infrastructure endpoint with an overall LOW RISK profile (Risk Score: 25/100). While historical observations indicate past threat activity, current signals show minimal risk characteristics consistent with legitimate cloud hosting infrastructure.
## Infrastructure Profile
- Organization: Linode (ASN: 63949)
- Infrastructure Type: Cloud Compute / Hosting
- Geolocation: Chicago, IL, US
- Network Classification: Cloud provider infrastructure
- DNS Resolution: 172-236-117-71.ip.linodeusercontent.com
- Forward Confirmation: Verified
## Active Services
| Port | Protocol | Service | Banner |
|---|---|---|---|
| 80 | TCP | HTTP | nginx/1.24.0 (Ubuntu) |
| 22 | TCP | SSH | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
HTTP endpoints return 301 redirect status codes.
## Threat Indicators
- Blacklist Count: 0
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- DNSBL Listings: 1 of 8 lists
- Abuse Confidence Score: Not available
## Historical Activity (26 observations)
- Most Recent: 2026-06-22 (Minimal risk label, confidence: 0.60)
- Notable Event: 2026-06-19 showed threat indicators via Alienvault-OTX with 12 correlated pulse events
- Threat Persistence: Single observation; not persistently malicious
- Signal Trend: Low to minimal risk signals across observation window
## Neighborhood Analysis
- Subnet: 172.236.117.71/24
- Abuse Density: 1 (Low)
- Classification: Mostly clean
- Threat Siblings: 1 (within /24)
- Inherited Risk: 2/10
## Relationship Graph
36 relationships identified, all classified as "Same Network" pointing to LINODE infrastructure. No cross-organization or external entity relationships detected.
## Recommended Actions
Based on risk score of 25, no immediate blocking or filtering actions are recommended. The IP demonstrates legitimate cloud hosting behavior with historical anomalies that have since normalized.
SOC Analyst Guidance: Monitor for any deviation from current low-risk profile. Historical threat indicators from June 2026 should be noted but do not warrant current defensive measures. Standard cloud infrastructure traffic patterns apply.
---
*Intelligence generated by IPDebrief platform. Data current as of analysis timestamp.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Linode |
| ASN | AS63949 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 172-236-117-71.ip.linodeusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 172-236-117-71.ip.linodeusercontent.com |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Multi-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 22 | ssh | tcp | |
| Closed Ports | 25, 443, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | nginx/1.24.0 (Ubuntu) |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 28% | 2 | 4 |
| ownership | 20% | 2 | 3 |
| reputation | 27% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 24% | 10 | 18 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:03:54 UTC |
| Last Seen | 2026-06-27 02:06:36 UTC |
| Profile Built | 2026-06-28 02:13:29 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 31 |
Full dossier details are available via our API.