# IP INTELLIGENCE BRIEFING: 172.237.156.107/32
Classification: Cloud Computing Infrastructure
Date: Current Assessment
Risk Level: LOW (Score: 25/100)
Status: Monitored
---
## EXECUTIVE SUMMARY
IP address 172.237.156.107 is a Linode cloud computing endpoint located in Chicago, Illinois, US. The IP operates within the 172.237.128.0/19 BGP prefix under ASN 63949. Current threat indicators show no active malicious activity. The endpoint is firewalled with no open services detected. Historical observation data confirms benign behavior with zero threat persistence and no known campaign associations.
---
## INFRASTRUCTURE PROFILE
| Attribute | Value |
|---|---|
| **IP Address** | 172.237.156.107 |
| **Organization** | Linode |
| **ASN** | 63949 |
| **CIDR Block** | 172.232.0.0/13 |
| **Geolocation** | US, Illinois, Chicago |
| **Infrastructure Type** | Cloud Compute |
| **Network Classification** | Cloud Hosting |
| **Bogon Status** | Clean |
Network Services: No open ports detected. No TLS certificates, HTTP banners, or reverse DNS entries. Service purpose classified as "Firewalled / No Services."
---
## THREAT ASSESSMENT
Risk Indicators
- Reputation Score: 25/100 (Low Risk)
- Abuse Confidence: Not applicable (clean profile)
- Blacklist Count: 0
- DNSBL Lists: 1/8 (Minimal operator risk)
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
Control Plane Analysis
- Route Stability: False (route changes detected)
- RPKI State: Not validated
- Operator Score: 0.1304 (Minimal)
- Threat Persistence: 0 days
- Malicious Observations: 0
---
## OBSERVATION HISTORY
The IP has generated 16 observation signals in the most recent period. Key observations include:
- Geolocation Signals: Consistent Chicago, Illinois placement with US-NY hop correlation
- Traceroute Analysis: 30-hop path through Comcast transit networks; 17 timeouts detected in middle hops
- Ownership Stability: Zero ownership changes recorded
- Threat Persistence: No persistent malicious behavior observed
- Campaign Correlation: Zero correlated IPs with campaign indicators
Temporal analysis shows no escalation in risk signals over the observation window.
---
## NETWORK NEIGHBORHOOD
Subnet: 172.237.156.107/24
Abuse Density: 0 (Clean)
Classification: Clean
Sibling Analysis:
- Total Siblings: 2
- Active Siblings: 2
- Threat Siblings: 0
Neighbor Risk Distribution:
| IP Address | Risk Score | Authority Score |
|---|---|---|
| 172.237.156.107 | 25 | N/A |
| 172.237.156.206 | 25 | 60 |
The /24 subnet demonstrates clean operational characteristics with no inherited risk from neighboring endpoints.
---
## RELATIONSHIP GRAPH
The IP maintains relationships with Linode network entities (5 relationships recorded). All relationships classified as "Same Network" with LINODE network designation. No external organization, hostname, or certificate associations detected.
---
## RECOMMENDED ACTIONS
Security Posture: No immediate action required.
Firewall Recommendations: No specific firewall rules generated (low-risk profile).
Monitoring Parameters:
- Continue standard cloud infrastructure monitoring
- No threat-based blocking recommended
- Monitor for service enumeration if ports become accessible
SOC Analyst Notes: This IP represents legitimate cloud infrastructure. The low risk score, absence of threat indicators, and clean neighborhood classification support continued observation without intervention. The single DNSBL listing and route instability warrant periodic review but do not indicate active compromise.
---
End of Briefing
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Linode |
| ASN | AS63949 |
| Network Name | LINODE |
| CIDR Block | 172.232.0.0/13 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 172-237-156-107.ip.linodeusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 172-237-156-107.ip.linodeusercontent.com |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 17% | 1 | 1 |
| Overall | 24% | 9 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-08-01 16:33:14 UTC |
| Last Seen | 2026-08-13 02:44:07 UTC |
| Profile Built | 2026-08-13 02:55:41 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.