# IP INTELLIGENCE BRIEFING: 172.252.13.101/32
Classification: MODERATE RISK (Score: 65/100)
Report Date: 2026-07-27
Analysis Period: Single observation window
---
## EXECUTIVE SUMMARY
IP address 172.252.13.101 is a web server endpoint operating on private network block 172.252.13.0/24. The asset demonstrates elevated risk characteristics due to moderate threat scoring (65/100), incomplete security header implementation, and geolocation data inconsistencies. No active malicious indicators detected at time of analysis, but monitoring recommendations warranted.
---
## TECHNICAL PROFILE
Network Identity
- IP Address: 172.252.13.101/32
- ASN: 53850
- Organization: Private Customer
- CIDR Block: 172.252.13.0/24
- Network Classification: Web Server
Service Fingerprint
- HTTP/HTTPS: nginx/1.24.0 (Ubuntu)
- Application Framework: Next.js
- Open Ports: 80/tcp (HTTP), 443/tcp (HTTPS), 22/tcp (SSH)
- TLS Certificate: Let's Encrypt (CN=myparentbridge.com)
---
## GEOLOCATION ANALYSIS
Reported Location: California, Los Angeles, US
Geolocation Consensus: FALSE
Critical Finding: RTT measurement violation detected. Observed RTT: 110.2ms average. Minimum possible RTT for reported distance (9,014 km): 180.3ms. This discrepancy indicates either:
- Inaccurate geolocation database data
- Potential routing manipulation
- Spoofed or falsified location information
---
## THREAT ASSESSMENT
Risk Score: 65/100 (Moderate Risk)
- Provider Score: 0
- Authority Score: 0
- Blacklist Count: 0
- Known Campaigns: None detected
Threat Indicators Status:
- Tor Exit Node: FALSE
- Known Attacker: FALSE
- Spam Source: FALSE
- DNSBL Listings: 3 of 8 total lists
Historical Analysis (17 Observations)
Recent signal observations show consistent web server behavior with no escalation of threat activity. No persistent malicious patterns observed across observation window.
---
## NEIGHBORHOOD INTELLIGENCE
Subnet: 172.252.13.0/24
Abuse Density: 0
Total Siblings: 1
Active Threat Siblings: 0
Neighbor Analysis:
- 172.252.13.90: Risk Score 0, Authority Score 50
The /24 subnet demonstrates minimal abuse activity, suggesting isolated risk profile for target IP.
---
## RELATIONSHIP MAPPING
Identified Relationships:
- Same Network: NET-172-252-13-0-24
No organizational, hostname, or certificate-based relationships detected beyond network-level association.
---
## SECURITY ACTIONS RECOMMENDATIONS
Monitoring
- Priority: HIGH
- Action: Increase logging verbosity and review recent activity from this IP
- Rationale: Elevated risk score (65/100) warrants enhanced observation
Firewall Rules
| Platform | Rule |
|---|---|
| **iptables** | `iptables -A INPUT -s 172.252.13.101 -j DROP` |
| **nftables** | `nft add rule inet filter input ip saddr 172.252.13.101 drop` |
| **nginx** | `deny 172.252.13.101;` |
| **pfSense** | `172.252.13.101/32` |
| **Cloudflare WAF** | Block IP (expression: `ip.src eq 172.252.13.101`) |
| **AWS WAF** | IP Set: 172.252.13.101/32 |
---
## SOC ANALYST NOTES
Key Concerns
1. Geolocation Inconsistency: 25%+ RTT discrepancy suggests data quality issues; may indicate routing anomalies or spoofing
2. Incomplete Security Posture: Missing HSTS, CSP, and proper DNS/email authentication (SPF/DMARC)
3. SSH Exposure: Port 22 open to external traffic increases attack surface
Recommended Additional Verification
- Cross-reference with internal network logs for this IP
- Validate TLS certificate validity and expiration
- Review connection patterns against baseline behavior
- Confirm network ownership and authorization status
---
END OF BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Private Customer |
| ASN | AS53850 |
| Network Name | NET-172-252-13-0-24 |
| CIDR Block | 172.252.13.0/24 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | 2/2 domains |
| DMARC | 2/2 domains |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
| Domains Checked | 2 domains |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 443 | https | tcp | — |
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | myparentbridge.comwww.myparentbridge.com |
| Valid From | 2026-07-11T04:09:23+00:00 |
| Valid Until | 2026-10-09T04:09:22+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
🛡️ Public Network Snapshot
| Origin ASN | AS53850 |
| Network Prefix | 172.252.13.0/24 |
| Route mapping | Found |
| HSTS | Not detected |
| CSP | Not detected |
| HTTP/2 | Not detected |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 31% | 2 | 3 |
| ownership | 19% | 2 | 2 |
| reputation | 18% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 22% | 10 | 14 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-15 10:08:41 UTC |
| Last Seen | 2026-09-29 20:35:34 UTC |
| Profile Built | 2026-09-27 02:40:40 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 27 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 172.252.13.101
Who owns the IP address 172.252.13.101?
172.252.13.101 is registered to Private Customer. The address falls within the 172.252.13.0/24 network block. Registration is held at ARIN.
Where is 172.252.13.101 located?
Geolocation data places 172.252.13.101 in Los Angeles, California, United States. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 172.252.13.101 malicious or safe?
172.252.13.101 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 172.252.13.101?
Responsive ports observed on 172.252.13.101 include 80, 443, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.