IP Intelligence Briefing: 172.94.9.166
Date: 2026-06-12
---
**1. Risk Profile**
- Overall Risk Score: Low (0/100)
- Threat Indicators: No malicious activity detected (no malware, phishing, or exploit campaigns).
- Network Classification: Firewalled / No Services (no open ports, TLS, or HTTP services).
- Ownership:
- Organization: Secure Internet LLC (UK)
- ASN: 213790 (LimitedNetwork-AS)
- Subnet: 172.94.9.0/24
- Geolocation: New York, NY, US (ARIN registered).
---
**2. Observation History**
- Recent Activity:
- 12 observations recorded over the past 30 days.
- Threat Feed Listings: 4/8 lists (confidence 0.85) with mixed severity (high, medium, low).
- DNSSEC Valid: Confirmed for reverse lookup (172.94.9.166.in-addr.arpa).
- Network Stability: Unstable BGP route (routeChanges30d = 0, isRouteStable = false).
---
**3. Network Relationships**
- Linked Entities:
- Subnet: 172.94.9.0/24 (owned by Secure Internet LLC).
- No direct links to domains, certificates, or organizations.
- Control Plane:
- BGP: ASN 213790 (LimitedNetwork-AS) with ARIN allocation (2015-06-02).
- DNSSEC: Validated for reverse DNS.
---
**4. Subnet Analysis**
- Neighbor IPs (172.94.9.0/24):
- Total Neighbors: 50 IPs.
- Abuse Density: 28% (moderate risk).
- High-Risk Neighbors: 14 IPs (e.g., 172.94.9.30β34, riskScore = 80).
- Low-Risk Neighbors: 8 IPs (e.g., 172.94.9.29, riskScore = 50).
---
**5. Actionable Intelligence**
- SOC Recommendations:
- Monitor high-risk neighbors (e.g., 172.94.9.30β34) for potential lateral movement or network compromise.
- Verify subnet segmentation policies to isolate low-risk IPs from high-risk subnets.
- Confirm DNSSEC validation and BGP route stability for the 172.94.9.0/24 subnet.
- Investigate why 4/8 threat feeds flag the subnet (potential false positives or undetected activity).
- Firewall Rules (Example):
```bash
# Block high-risk neighbors (adjust based on actual IPs)
iptables -A INPUT -s 172.94.9.30/32 -j DROP
iptables -A INPUT -s 172.94.9.31/32 -j DROP
```
---
Conclusion:
The IP 172.94.9.166 is low-risk but resides in a subnet with moderate abuse density. Focus on monitoring neighboring IPs and validating network segmentation to mitigate potential risks. No immediate action required for the IP itself, but proactive subnet analysis is advised.
Tools Used: ipdebrief_profile, ipdebrief_history, ipdebrief_relationships, ipdebrief_neighbors.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Secure Internet LLC (UK) |
| ASN | AS213790 |
| Network Name | INTERNET-SECURITY-LIMITED-NETWORK |
| CIDR Block | 172.94.9.0/24 |
| RIR | ARIN |
| Country | United Kingdom |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 27% | 2 | 3 |
| reputation | 0% | 0 | 0 |
| geolocation | 13% | 1 | 1 |
| Overall | 6% | 3 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-06-04 00:31:34 UTC |
| Last Seen | 2026-06-26 18:10:47 UTC |
| Profile Built | 2026-06-12 23:34:24 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 16 |
Full dossier details are available via our API.