IPDebrief

172.252.13.101

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING: 172.252.13.101/32

Classification: MODERATE RISK (Score: 65/100)

Report Date: 2026-07-27

Analysis Period: Single observation window

---

## EXECUTIVE SUMMARY

IP address 172.252.13.101 is a web server endpoint operating on private network block 172.252.13.0/24. The asset demonstrates elevated risk characteristics due to moderate threat scoring (65/100), incomplete security header implementation, and geolocation data inconsistencies. No active malicious indicators detected at time of analysis, but monitoring recommendations warranted.

---

## TECHNICAL PROFILE

Network Identity

Service Fingerprint

---

## GEOLOCATION ANALYSIS

Reported Location: California, Los Angeles, US

Geolocation Consensus: FALSE

Critical Finding: RTT measurement violation detected. Observed RTT: 110.2ms average. Minimum possible RTT for reported distance (9,014 km): 180.3ms. This discrepancy indicates either:

---

## THREAT ASSESSMENT

Risk Score: 65/100 (Moderate Risk)

Threat Indicators Status:

Historical Analysis (17 Observations)

Recent signal observations show consistent web server behavior with no escalation of threat activity. No persistent malicious patterns observed across observation window.

---

## NEIGHBORHOOD INTELLIGENCE

Subnet: 172.252.13.0/24

Abuse Density: 0

Total Siblings: 1

Active Threat Siblings: 0

Neighbor Analysis:

The /24 subnet demonstrates minimal abuse activity, suggesting isolated risk profile for target IP.

---

## RELATIONSHIP MAPPING

Identified Relationships:

No organizational, hostname, or certificate-based relationships detected beyond network-level association.

---

## SECURITY ACTIONS RECOMMENDATIONS

Monitoring

Firewall Rules

PlatformRule
**iptables**`iptables -A INPUT -s 172.252.13.101 -j DROP`
**nftables**`nft add rule inet filter input ip saddr 172.252.13.101 drop`
**nginx**`deny 172.252.13.101;`
**pfSense**`172.252.13.101/32`
**Cloudflare WAF**Block IP (expression: `ip.src eq 172.252.13.101`)
**AWS WAF**IP Set: 172.252.13.101/32

---

## SOC ANALYST NOTES

Key Concerns

1. Geolocation Inconsistency: 25%+ RTT discrepancy suggests data quality issues; may indicate routing anomalies or spoofing

2. Incomplete Security Posture: Missing HSTS, CSP, and proper DNS/email authentication (SPF/DMARC)

3. SSH Exposure: Port 22 open to external traffic increases attack surface

Recommended Additional Verification

---

END OF BRIEFING

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇺🇸 United States
RegionCalifornia
CityLos Angeles
Timezone—
Latitude34.05
Longitude-118.24

🏢 Ownership & Registration

OrganizationPrivate Customer
ASNAS53850
Network NameNET-172-252-13-0-24
CIDR Block172.252.13.0/24
RIRARIN
CountryUnited States
Abuse Contact—

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)

🔐 DNS Hygiene

Hygiene Score40% (Fair)
SPF2/2 domains
DMARC2/2 domains
FCrDNSNot verified
DNSSECNot signed
CAANot configured
Domains Checked2 domains

☁️ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierUnknown — Insufficient routing data to classify
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
80httptcp—
443httpstcp—
22sshtcpBanner detected
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
ServerWeb server detected
HTTP Title—

🔐 TLS Certificate

🔒
CN=myparentbridge.com
Issued by CN=YE1, O=Let's Encrypt, C=US
Self-signed: No
SANsmyparentbridge.comwww.myparentbridge.com
Valid From2026-07-11T04:09:23+00:00
Valid Until2026-10-09T04:09:22+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha384ECDSA
Validity Period89 days

🛡️ Public Network Snapshot

Origin ASNAS53850
Network Prefix172.252.13.0/24
Route mappingFound
HSTSNot detected
CSPNot detected
HTTP/2Not detected

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
27%
23
routing
13%
11
services
31%
23
ownership
19%
22
reputation
18%
12
geolocation
27%
23
Overall22%1014
Coverage: 6/6 dimensions · Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) — 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Claimed geolocation contradicts RTT physics measurement

📅 Observation Timeline 🔄 Live

First Seen2026-07-15 10:08:41 UTC
Last Seen2026-09-29 20:35:34 UTC
Profile Built2026-09-27 02:40:40 UTC
Data FreshnessLive
Signal Types21
Total Observations27
🔍 21 signal types · 27 observations collected
This report is generated from 21+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 172.252.13.101

Who owns the IP address 172.252.13.101?

172.252.13.101 is registered to Private Customer. The address falls within the 172.252.13.0/24 network block. Registration is held at ARIN.

Where is 172.252.13.101 located?

Geolocation data places 172.252.13.101 in Los Angeles, California, United States. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 172.252.13.101 malicious or safe?

172.252.13.101 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.

What ports are open on 172.252.13.101?

Responsive ports observed on 172.252.13.101 include 80, 443, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.

🏘️ Related IP Addresses

Nearby addresses in 172.252.13.0/24

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.