IPDebrief

173.225.111.78

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 173.225.111.78/32

## Executive Summary

IP address 173.225.111.78 is a moderate-risk (55/100) infrastructure endpoint owned by Interserver, Inc (ASN 19318). The address hosts within the 173.225.96.0/20 block and presents elevated risk primarily through open RDP services and DNSBL listings. No active threat indicators were detected, but monitoring is recommended due to service exposure.

---

## Infrastructure Profile

Ownership: Interserver, Inc | ASN 19318 | Network: INTER-83

Registration: ARIN | CIDR Block: 173.225.96.0/20

Geolocation: United States (2500km accuracy radius)

Network Role: Single-Service Host | Not classified as CDN, Cloud, VPN, or Proxy

---

## Risk Assessment

Overall Risk Score: 55 (Moderate)

Abuse Confidence: Not applicable

DNSBL Listings: 3 of 8 total lists

Operator Score: 0.1304 (Minimal)

Risk Factors Identified:

Mitigating Factors:

---

## Network Services

Open Ports:

DNS Analysis:

---

## Threat Intelligence

Threat Indicators: None detected

Known Campaigns: None

Blacklist Sources: 3 listings (specific feeds not enumerated)

Campaign Likelihood: Not correlated

Observation History: 16 signals observed

---

## Neighborhood Analysis

Subnet: 173.225.111.78/24

Abuse Density: 0 (Clean)

Neighbor Count: 0

Threat Siblings: 0

Classification: Clean

---

## Recommended Actions

Immediate Recommendations

1. Monitoring: Increase logging verbosity and review recent activity from this IP

2. Firewall: Consider blocking or rate-limiting based on organizational policy

Platform-Specific Rules

iptables:

```

iptables -A INPUT -s 173.225.111.78 -j DROP

```

nftables:

```

nft add rule inet filter input ip saddr 173.225.111.78 drop

```

nginx:

```

deny 173.225.111.78;

```

pfSense:

```

173.225.111.78/32

```

Cloudflare WAF:

```json

{"description":"Block 173.225.111.78 β€” IPDebrief risk score 55","action":"block","filter":{"expression":"ip.src eq 173.225.111.78"}}

```

AWS WAF:

```json

{"Addresses":["173.225.111.78/32"],"Description":"IPDebrief risk 55"}

```

---

## Intelligence Narrative

The IP 173.225.111.78 is a commercial hosting endpoint that presents moderate risk due to exposed RDP services and DNSBL listings. While no active attack signatures were detected, the open RDP port represents a potential lateral movement vector if compromised. The subnet shows zero abuse density, indicating this is an isolated risk rather than part of a coordinated campaign. SOC analysts should monitor for port scanning activity and consider blocking based on RDP exposure policies. The IP's BGP route instability suggests potential hosting infrastructure changes that may affect long-term threat assessment.

Classification: Moderate Risk - Monitor

Last Updated: 2026-07-30

Data Source: IPDebrief Intelligence Platform

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
Regionβ€”
CityNew York
Timezoneβ€”
Latitudeβ€”
Longitudeβ€”

🏒 Ownership & Registration

OrganizationInterserver, Inc
ASNAS19318
Network NameINTER-83
CIDR Block173.225.96.0/20
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)

πŸ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeSingle-Service Host
Network TierUnknown β€” Insufficient routing data to classify
No specific classification

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
3389rdptcpβ€”
Closed Ports22, 25, 80, 443, 8080, 8443 (1 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
25%
12
reputation
0%
00
geolocation
25%
11
Overall20%56
Coverage: 5/6 dimensions Β· Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-07-26 09:12:03 UTC
Last Seen2026-08-13 06:44:06 UTC
Profile Built2026-07-30 07:24:51 UTC
Data FreshnessLive
Signal Types18
Total Observations18
πŸ” 18 signal types Β· 18 observations collected
This report is generated from 18+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.