# IP INTELLIGENCE BRIEFING
## Target: 172.245.102.73/32
Classification: LOW RISK / NON-THREAT
Date: 2026-07-29
---
EXECUTIVE SUMMARY
IP address 172.245.102.73 is classified as a low-risk endpoint with no active threat indicators. The IP belongs to a private customer subnet with minimal abuse density and demonstrates stable network behavior across observation periods.
---
PROFILE OVERVIEW
Risk Assessment: Risk Score 25/100 (Low Risk)
Reputation: Low Risk
ASN: 212238
Organization: Private Customer
CIDR Block: 172.245.102.0/24
Geolocation: United States, California, Los Angeles (2500km accuracy)
Network Classification:
- Infrastructure Type: Firewalled / No Services
- No open ports detected
- Not identified as CDN, proxy, VPN, Tor exit, hosting, or mobile carrier
- DNSSEC validation: Valid
---
THREAT INTELLIGENCE
Threat Indicators: None detected
Blacklist Status: 0/0 lists (no active listings)
Abuse Confidence Score: Not applicable
Known Campaigns: None
Threat Feeds: Empty
Observed Behaviors:
- No open services detected
- No TLS certificates or HTTP fingerprints
- No SMTP/SSH/HTTP server banners
- No known attacker reputation
---
NETWORK CONTEXT
DNS Resolution: 172-245-102-73-host.colocrossing.com
PTR Records: 172-245-102-73-host.colocrossing.com
Forward Resolution: Confirmed (1 record)
Email Auth: SPF record present
Control Plane:
- BGP Prefix: 172.245.102.0/24
- Route Stability: Unstable (0 route changes in 30 days)
- DNSBL Listed: 1 of 8 total lists
---
NEIGHBORHOOD ANALYSIS
Subnet: 172.245.102.0/24
Abuse Density: 0 (Clean classification)
Total Siblings: 26
Active Siblings: 16
Threat Siblings: 0
Risk Distribution in Subnet:
- High Risk: 0 IPs
- Medium Risk: 4 IPs
- Low Risk: 22 IPs
Notable Neighbors:
- 172.245.102.5, 172.245.102.88, 172.245.102.93: Risk Score 60 (medium concern)
- Remaining neighbors: Risk Score 0-25
---
OBSERVATION HISTORY
Total Observations: 19 signals recorded
Recent Activity: No significant behavioral changes
Threat Persistence Days: 0
Persistent Malicious Activity: False
Ownership Changes: 0
Recent Signals:
- Subnet classification: Clean (abuse density: 0)
- Network role: No services detected
- Tor/VPN/Proxy: Negative
- Persistent threats: None
---
RELATIONSHIP GRAPH
Entity Types: 11 relationships identified
- Same Network: NET-172-245-102-0-24 (multiple entries)
- DNS Associations: 172-245-102-73-host.colocrossing.com (multiple entries)
---
RECOMMENDATIONS
Security Actions: No firewall rules required
Classification: Safe for general traffic
Monitoring Level: Standard (no elevated monitoring needed)
---
INTELLIGENCE JUDGMENT
This IP address represents a benign, non-threatening endpoint with no malicious indicators. The subnet maintains low abuse density with minimal medium-risk neighbors. No defensive actions or blocking recommendations are warranted at this time. Standard logging and monitoring practices apply.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Private Customer |
| ASN | AS212238 |
| Network Name | NET-172-245-102-0-24 |
| CIDR Block | 172.245.102.0/24 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | β |
π DNS Intelligence
| PTR | 172-245-102-73-host.colocrossing.com |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 172-245-102-73-host.colocrossing.com |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 3 |
| routing | 20% | 1 | 1 |
| services | 28% | 2 | 2 |
| ownership | 28% | 2 | 2 |
| reputation | 20% | 1 | 2 |
| geolocation | 20% | 1 | 1 |
| Overall | 26% | 9 | 11 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-23 20:05:16 UTC |
| Last Seen | 2026-08-02 17:02:00 UTC |
| Profile Built | 2026-08-01 04:38:42 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.