# IP INTELLIGENCE BRIEFING: 172.238.186.89/32
Date: 2026-08-05
Classification: Low Risk / Cloud Infrastructure
Analyst: IPDebrief Intelligence Team
---
## EXECUTIVE SUMMARY
IP address 172.238.186.89 is a cloud-hosted web server operated by Linode (ASN: 63949) with a risk score of 25/100. The asset represents legitimate infrastructure hosting Cloudways applications and shows no evidence of malicious activity. The IP operates within a clean subnet with zero abuse density.
---
## OWNERSHIP & INFRASTRUCTURE
| Attribute | Value |
|---|---|
| **Organization** | Linode |
| **NetName** | LINODE |
| **ASN** | 63949 |
| **Country** | United States (IL) |
| **City** | Chicago |
| **Infrastructure** | Cloud Compute |
| **Classification** | Web Server / Hosting |
Network Role: The IP is classified as a cloud computing host with active web services. Forward DNS resolution confirms the hostname `172-238-186-89.ip.linodeusercontent.com`.
---
## THREAT ASSESSMENT
Risk Score: 25 (Low Risk)
Threat Indicators:
- No known campaigns or threat feeds
- Not a known attacker, spam source, or Tor exit node
- Zero blacklist hits in threat intelligence feeds
- Abuse confidence score: Not applicable (legitimate hosting)
Control Plane Analysis:
- BGP Prefix: 172.238.160.0/19
- Route Stability: Flagged as unstable (isRouteStable: false)
- DNSSEC: Valid
- DNSBL Listed: 1 of 8 total lists checked (operatorScore: 0.2609)
---
## NETWORK SERVICES & FINGERPRINTING
Open Ports:
- TCP/80 (HTTP)
- TCP/443 (HTTPS)
- TCP/22 (SSH - OpenSSH_9.2p1 Debian)
SSL/TLS Certificate:
- Issuer: Sectigo Public Server Authentication CA DV R36
- Subject: *.cloudwaysapps.com
- Certificate Validity: Active
- Self-Signed: No
Server Fingerprint:
- Web Server: nginx
- HTTP Version: 2.0
- HTTP Status: 403 (Forbidden) on recent probe
- HSTS: Not enabled
- CSP: Not configured
---
## NEIGHBORHOOD ANALYSIS
Subnet: 172.238.186.89/24
- Abuse Density: 0 (Clean)
- Classification: Clean
- Sibling IPs: 1 active sibling
- Threat Siblings: 0
The /24 subnet shows no malicious activity and demonstrates normal cloud hosting behavior.
---
## OBSERVATION HISTORY
Total Observations: 23 signals over monitoring period
Recent Activity:
- 2026-08-05: Port scanning activity detected
- 2026-08-05: Network operator score assessment (Basic)
- 2026-07-29: HTTP response analysis (403 Forbidden)
- 2026-07-29: Subnet classification verified as clean
Persistence: No persistent malicious indicators. IP shows standard hosting activity patterns with no evidence of campaign participation.
---
## RELATIONSHIP GRAPH
Primary Associations:
- DNS Hostname: 172-238-186-89.ip.linodeusercontent.com (13 relationship entries)
- Network: LINODE (Same Network)
No suspicious external relationships detected. All associations confirm legitimate Linode cloud infrastructure.
---
## RECOMMENDATIONS
Security Actions:
- No immediate blocking or mitigation required
- Monitor for policy violations on port 22 (SSH) if not expected in your environment
- Standard logging recommended for baseline traffic analysis
Firewall Rules:
- Allow: TCP/80, TCP/443 (standard web traffic)
- Review: TCP/22 access based on organizational policy
- No action on DNSBL listing (likely false positive for cloud hosting)
---
## CONCLUSION
IP 172.238.186.89/32 is a legitimate Linode cloud computing host operating Cloudways web applications. The IP demonstrates low-risk characteristics with no threat indicators, clean neighborhood context, and standard web server behavior. No defensive action required at this time.
Status: MONITOR / LOW RISK
---
*Report generated by IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Linode |
| ASN | AS63949 |
| Network Name | LINODE |
| CIDR Block | 172.232.0.0/13 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 172-238-186-89.ip.linodeusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 172-238-186-89.ip.linodeusercontent.com |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | nginx |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 19% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 15% | 1 | 2 |
| geolocation | 13% | 1 | 1 |
| Overall | 19% | 9 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-23 20:05:16 UTC |
| Last Seen | 2026-08-12 17:58:21 UTC |
| Profile Built | 2026-08-12 18:06:49 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 27 |
Full dossier details are available via our API.