# IP INTELLIGENCE BRIEFING: 172.237.87.100/32
Classification: Cloud Infrastructure Host (Linode)
Date: 2026-07-30
Risk Rating: MODERATE (Score: 50/100)
---
## EXECUTIVE SUMMARY
The target IP address (172.237.87.100) is a Linode cloud compute host with a moderate risk profile. The IP is associated with Linode's cloud infrastructure (ASN 63949) and resolves to Singapore geolocation data. No active threat indicators were detected, though the IP shows 2 DNSBL listings. The subnet exhibits clean classification with zero abuse density.
---
## OWNERSHIP & INFRASTRUCTURE
- Organization: Linode (LINODE)
- ASN: 63949
- CIDR Block: 172.232.0.0/13
- Infrastructure Type: CloudCompute / Hosting
- DNS Name: 172-237-87-100.ip.linodeusercontent.com
- Forward Resolution: Confirmed (1 hostname)
---
## GEOLOCATION ANALYSIS
- Primary Location: Singapore (SG)
- Alternative Signal: US (39.83, -98.58)
- Consensus: Multiple geolocation sources with conflicting data
- Accuracy Radius: 2,500 km
- Assessment: Cloud-hosted IP with typical geo-attribution variance
---
## THREAT INTELLIGENCE
- Abuse Confidence Score: Not available
- Blacklist Status: 2 DNSBL listings (of 8 total)
- Threat Indicators: None detected
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Known Campaigns: None
---
## NETWORK SERVICES
- Open Ports: None detected
- TLS Certificate: None
- HTTP Banner: None
- Service Status: Firewalled / No Services
- Scan Activity: Recent port scanning observed (2026-07-30 18:55:08 UTC)
---
## NEIGHBORHOOD ANALYSIS
- Subnet: 172.237.87.100/24
- Abuse Density: 0 (Clean)
- Threat Siblings: 0
- Active Siblings: 0
- Inherited Risk: 0
---
## OBSERVATION HISTORY
Total Observations: 17 signals recorded
Recent Activity (2026-07-30):
- 18:58:14 UTC - Ownership/stability signal (confidence 0.85)
- 18:55:08 UTC - Port scanning detected (confidence 0.70)
- 18:54:58 UTC - Geolocation signal: US (confidence 0.35)
- 18:54:53 UTC - Subnet classification: Clean (confidence 0.40)
- 18:53:52 UTC - Geolocation signal: Singapore (confidence 0.70)
Temporal Indicators:
- No persistent malicious behavior
- Zero threat observation persistence
- No ownership changes recorded
---
## RELATIONSHIP GRAPH
Associated Entities:
- DNS: 172-237-87-100.ip.linodeusercontent.com (3 associations)
- Network: LINODE (2 associations)
---
## SECURITY ACTIONS
Recommendations: Standard cloud infrastructure monitoring. No immediate blocking required. DNSBL listings suggest monitoring for reputation degradation.
Firewall Rules: No specific rules generated due to moderate risk profile and lack of active threats.
---
## ANALYST NOTES
The IP address exhibits characteristics typical of legitimate Linode cloud hosting. The moderate risk score (50) is driven primarily by DNSBL listings rather than active malicious behavior. Port scanning activity was observed but no services were found open. Geolocation data shows expected variance common with cloud providers. No correlation to known threat campaigns or malicious infrastructure was detected.
Priority Level: LOW
Recommended Action: Routine monitoring; no immediate mitigation required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Linode |
| ASN | AS63949 |
| Network Name | LINODE |
| CIDR Block | 172.232.0.0/13 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 172-237-87-100.ip.linodeusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 172-237-87-100.ip.linodeusercontent.com |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 33% | 2 | 4 |
| Overall | 23% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-28 22:21:57 UTC |
| Last Seen | 2026-08-12 22:53:02 UTC |
| Profile Built | 2026-08-12 23:03:40 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 22 |
Full dossier details are available via our API.