# IP INTELLIGENCE BRIEFING
## Target: 172.239.98.194/32
Date: June 2026
Classification: Low Risk - Cloud Infrastructure
Risk Score: 25/100
---
EXECUTIVE SUMMARY
IP address 172.239.98.194 is identified as legitimate Linode cloud infrastructure with low-risk characteristics. No active malicious indicators detected. Suitable for monitoring without immediate blocking action.
---
OWNERSHIP & NETWORK CLASSIFICATION
| Field | Value |
|---|---|
| **Organization** | Linode |
| **ASN** | 63949 |
| **Country** | US |
| **Infrastructure Type** | CloudCompute |
| **Network Role** | Hosting Provider |
| **CIDR Block** | 172.239.96.0/19 |
The IP is classified as cloud hosting infrastructure (Linode platform) with no proxy, VPN, Tor, or residential indicators.
---
THREAT INDICATORS
| Indicator | Status |
|---|---|
| **Reputation** | Low Risk |
| **Known Attacker** | No |
| **Spam Source** | No |
| **Tor Exit Node** | No |
| **Blacklist Count** | 0 |
| **Abuse Confidence** | Not applicable |
| **Campaign Affiliation** | None detected |
---
GEOLOCATION DATA
- Country: United States (US)
- Region/City: London, England (note: geolocation accuracy radius 2500km due to cloud infrastructure)
- Geo Confidence: Consensus valid across 1 source
---
DNS & NETWORK SERVICES
| Parameter | Value |
|---|---|
| **PTR Hostname** | 172-239-98-194.ip.linodeusercontent.com |
| **Forward Resolution** | Confirmed |
| **Open Ports** | None detected (firewalled) |
| **TLS Certificate** | N/A |
| **HTTP Services** | None detected |
| **DNSSEC Valid** | Yes |
The IP shows no active services; connection type indicates "Firewalled / No Services."
---
SUBNET ANALYSIS (172.239.98.0/24)
| Metric | Value |
|---|---|
| **Abuse Density** | 0 |
| **Classification** | mostly_clean |
| **Inherited Risk** | 5 |
| **Total Siblings** | 2 |
| **Threat Siblings** | 2 |
Only one neighbor IP (172.239.98.23) detected in subnet, both with low risk scores. Subnet shows minimal abuse activity.
---
OBSERVATION HISTORY (21 Signals)
Recent activity concentrated on June 20, 2026:
- Provider Classification: Linode cloud infrastructure (confidence: 0.85)
- Geolocation: US region (confidence: 0.35)
- Operator Score: 0.2609 (Basic classification)
- Port Scanning: June 15, 2026 - No active services exposed
- Threat Persistence: 0 days (no persistent malicious behavior)
---
RELATIONSHIP GRAPH
Primary Associations:
- DNS: 172-239-98-194.ip.linodeusercontent.com (multiple records)
- Network: LINODE
- No organizational or certificate relationships detected
Total: 45 relationship entries, primarily DNS associations.
---
RECOMMENDED ACTIONS
Current Risk Level: Low (25/100)
Action Items:
- Monitor: Continue passive observation
- Block: Not recommended
- Allow: Permissive firewall rules appropriate
- Investigate: No immediate indicators requiring escalation
Note: No specific firewall rules generated due to low risk profile. Standard cloud infrastructure policies apply.
---
INTELLIGENCE CONCLUSION
IP 172.239.98.194 represents legitimate Linode cloud computing infrastructure with no malicious indicators. The IP is properly registered, DNS-resolved, and classified as hosting infrastructure. Subnet analysis confirms minimal abuse activity. No action required beyond routine monitoring.
Threat Level: LOW
Recommended Handling: PASSIVE MONITOR
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Linode |
| ASN | AS63949 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 172-239-98-194.ip.linodeusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 172-239-98-194.ip.linodeusercontent.com |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 24% | 2 | 3 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-21 08:54:38 UTC |
| Last Seen | 2026-06-28 13:09:53 UTC |
| Profile Built | 2026-06-29 07:14:44 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 25 |
Full dossier details are available via our API.