INTELLECT BRIEFING: IP 173.239.214.27/32
Classification: Low Risk | Threat Level: Minimal
---
1. IP Profile & Ownership
IP address 173.239.214.27 is registered to LOGICWEB (ASN 62240), a private customer organization within the 173.239.214.0/24 CIDR block. Geographic location is registered to Ashburn, Virginia, US. The IP maintains a risk score of 25, classified as Low Risk. No active threat indicators, blacklist listings, or known campaign associations were detected.
2. Network Classification
The IP is not categorized as cloud, CDN, VPN, proxy, Tor, hosting, mobile, or residential infrastructure. Service profile indicates "Firewalled / No Services" with no open ports, TLS certificates, or email authentication records (SPF/DMARC absent). The control plane shows DNSSEC validation enabled, minimal operator score (0.1304), and route stability flagged as false.
3. Historical Observations
Analysis of 16 historical observations reveals:
- Recent geolocation probes (2026-06-22) showed RTT violations, with measured 23-31ms RTT inconsistent with claimed 6,008km distance (minimum possible RTT: 120.16ms)
- On 2026-06-17, one of eight blacklist listings was flagged with high severity
- Subnet abuse density observed at 0.4889 with mixed classification
- No persistent malicious behavior detected over the observation window
4. Neighborhood Analysis (173.239.214.0/24)
The /24 subnet contains 45 sibling IPs with the following distribution:
- High Risk: 0
- Medium Risk: 16
- Low Risk: 29
- Active siblings: 13
- Threat siblings: 22
Notable neighbors include 173.239.214.6, 173.239.214.8, 173.239.214.12, and 173.239.214.19 (all risk score 40). Inherited risk score from neighborhood: 19.
5. Relationships
Network relationships indicate all 16 detected associations point to LOGICWEB network infrastructure. No external organizational or hostname relationships beyond the network designation were identified.
---
SOC ACTIONS & RECOMMENDATIONS
1. Block Status: No blocking required. Low-risk profile with no active threat indicators.
2. Firewall Rules: No specific firewall rules generated due to minimal risk profile.
3. Monitoring: Monitor for changes in service profile (open ports, TLS certificates) or blacklist status changes.
4. Geolocation: Verify actual location via traffic analysis; RTT violations suggest potential proxy usage or misconfiguration.
5. Subnet Context: While the subnet shows mixed abuse density (0.4889), this specific IP shows no malicious activity. Contextual analysis recommended for any suspicious traffic originating from sibling IPs.
Priority: LOW β No immediate action required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Private Customer |
| ASN | AS62240 |
| Network Name | LOGICWEB |
| CIDR Block | 173.239.214.0/24 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | β |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 19% | 2 | 2 |
| reputation | 17% | 1 | 2 |
| geolocation | 37% | 2 | 3 |
| Overall | 20% | 9 | 11 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:03:55 UTC |
| Last Seen | 2026-06-22 21:31:03 UTC |
| Profile Built | 2026-06-22 21:42:02 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.