IPDebrief

172.239.26.175

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING

Subject: 172.239.26.175/32

Date: Current Analysis

Classification: Low Risk – Cloud Infrastructure

---

## EXECUTIVE SUMMARY

IP 172.239.26.175 is a Linode cloud compute instance (ASN 63949) presenting low-risk characteristics. The IP is classified as a single-service host with cloud hosting infrastructure. No active threat indicators or known malicious campaigns were detected. The subnet (172.239.26.0/24) shows minimal abuse density (0.0), with no neighboring threat indicators.

---

## OWNERSHIP & INFRASTRUCTURE

---

## THREAT INDICATORS

IndicatorStatus
Risk Score25 (Low)
Known AttackerNo
Tor Exit NodeNo
Proxy/VPNNo
Spam SourceNo
Blacklist Count1 of 8 DNSBLs
Abuse ConfidenceNot Flagged
Known CampaignsNone

---

## NETWORK SERVICES

- Banner: `SSH-2.0-OpenSSH_10.0p2 Debian-7`

---

## SUBNET CONTEXT (172.239.26.0/24)

---

## OBSERVATION HISTORY

Recent signal observations indicate consistent cloud infrastructure behavior:

1. Infrastructure Classification: Confirmed as cloud hosting (confidence: 0.90)

2. SSH Service: Debian-based OpenSSH 10.0p2 detected

3. Operator Score: Basic (0.2609)

4. Control Plane: Route stability issues flagged; BGP prefix 172.239.0.0/19

5. DNSBL Status: Listed on 1 of 8 total lists

---

## RELATIONSHIP ANALYSIS

---

## SECURITY RECOMMENDATIONS

Based on the risk profile (Score: 25), the following actions are recommended:

1. Monitor SSH Traffic: The open SSH port indicates active host management. Monitor for unusual login attempts or brute force activity.

2. DNSBL Verification: Investigate the single DNSBL listing to determine the nature of the listing (false positive vs. policy violation).

3. Control Plane Review: Monitor BGP route changes for the 172.239.0.0/19 prefix.

4. No Blocking Required: Current risk score does not warrant blocking; allow traffic with logging enabled.

5. Geolocation Consistency: Verify geolocation data against known Linode datacenter locations.

---

## CONCLUSION

IP 172.239.26.175 is a legitimate cloud hosting instance with low-risk characteristics. No evidence of active malicious activity was detected. The single DNSBL listing warrants periodic verification but does not indicate immediate threat. Recommended approach: Allow with monitoring, no blocking required.

---

*Analysis generated using IPDebrief Intelligence Platform*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionÎle-de-France
CityParis
Timezoneβ€”
Latitude48.86
Longitude2.35

🏒 Ownership & Registration

OrganizationLinode
ASNAS63949
Network Nameβ€”
CIDR Blockβ€”
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR172-239-26-175.ip.linodeusercontent.com
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnames172-239-26-175.ip.linodeusercontent.com

πŸ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeSingle-Service Host
Network TierHosting β€” Infrastructure provider without advanced routing
Hosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
22sshtcp
Closed Ports25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”
SSH VersionSSH-2.0-OpenSSH_10.0p2 Debian-7

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
22%
24
routing
13%
11
services
20%
23
ownership
24%
23
reputation
24%
13
geolocation
30%
23
Overall22%1017
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-08 05:01:49 UTC
Last Seen2026-06-27 12:30:46 UTC
Profile Built2026-06-28 12:34:37 UTC
Data FreshnessLive
Signal Types23
Total Observations30
πŸ” 23 signal types Β· 30 observations collected
This report is generated from 23+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.