THREAT INTELLIGENCE BRIEFING
Target IP: 173.255.221.151
Classification: Cloud Infrastructure (Linode)
Date of Analysis: 2026-06-16
---
## EXECUTIVE SUMMARY
IP address 173.255.221.151 is a Linode cloud compute instance (AS63949) located in Fremont, CA. The asset presents LOW RISK with an overall risk score of 25/100. The IP is currently listed on 1 of 8 DNS blacklists. No active malicious campaigns or known attack patterns were detected.
---
## INFRASTRUCTURE PROFILE
| Attribute | Value |
|---|---|
| **Organization** | Linode LLC (AS63949) |
| **Network Block** | 173.255.192.0/18 |
| **Geolocation** | Fremont, CA, US |
| **Infrastructure Type** | Cloud Compute (Hosting) |
| **Connection Type** | Single-Service Host |
| **DNS Resolution** | prod-boron-us-west-10.li.binaryedge.ninja |
---
## NETWORK CHARACTERISTICS
Open Services:
- Port 22/TCP: SSH (OpenSSH 8.9p1 Ubuntu-3ubuntu0.15)
Control Plane Data:
- Route Stability: UNSTABLE (isRouteStable: false)
- DNSSEC: Valid
- DNSBL Lists: 1/8 total lists
- Operator Score: 0.2609 (Basic)
---
## THREAT INDICATORS
Current Risk Assessment:
- Risk Score: 25/100 (Low Risk)
- Abuse Confidence Score: Not available
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0 (profile-level), 1 (DNSBL)
- Active Threat Campaigns: None
GeoValidation:
- RTT vs Distance: Violation detected
- Minimum Possible RTT: 176.9ms
- Observed RTT: 81.0ms
- Distance: 8,843.8km
- Note: Geographic discrepancy detected; RTT inconsistent with reported location
---
## NEIGHBORHOOD ANALYSIS (173.255.221.0/24)
| Metric | Value |
|---|---|
| Subnet Classification | Mostly Clean |
| Abuse Density | 0.5/1.0 (Moderate) |
| Inherited Risk | 2 |
| Total Siblings | 2 |
| Active Siblings | 1 |
| Threat Siblings | 1 |
Identified Threat Neighbor:
- 173.255.221.189: Risk Score 50/100, Authority Score 60/100
- Recommendation: Monitor this neighboring IP for coordinated activity
---
## OBSERVATION HISTORY
Total Observations: 22
Recent Activity (2026-06-16):
- Subnet classification: Mostly Clean (abuse_density: 0.5)
- Threat pulses detected: 9 (source: AlienVault OTX)
- Operator assessment: Basic (raw_score: 0.3)
- Overall confidence: 0.2575
Threat Persistence: 0 days
Ownership Changes: 0
---
## RELATIONSHIP GRAPH
Total Relationships: 18
Key Associations:
- Multiple Same Network relationships to LINODE infrastructure
- DNS Association: prod-boron-us-west-10.li.binaryedge.ninja (repeated multiple times)
---
## SECURITY RECOMMENDATIONS
Current Status: No specific firewall rules or blocking recommendations generated due to low-risk profile.
Suggested Monitoring Actions:
1. Monitor neighboring IP 173.255.221.189 for elevated activity
2. Investigate DNS blacklist listing (1/8 lists)
3. Consider geovalidation discrepancy during incident triage
4. Monitor for route stability changes
Classification Flags:
- Cloud Infrastructure: Yes
- CDN: No
- VPN: No
- Proxy: No
- Hosting: Yes
- Mobile: No
- Residential: No
- Bogon: No
---
## CONCLUSION
The target IP 173.255.221.151 represents low-risk cloud infrastructure hosted on Linode. No immediate threat indicators warrant blocking. SOC analysts should monitor the associated subnet for the identified threat sibling (173.255.221.189) and maintain awareness of the geographic validation discrepancy.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Linode |
| ASN | AS63949 |
| Network Name | LINODE |
| CIDR Block | 173.255.192.0/18 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | prod-boron-us-west-10.li.binaryedge.ninja |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | prod-boron-us-west-10.li.binaryedge.ninja |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 23% | 10 | 14 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-06-03 12:21:09 UTC |
| Last Seen | 2026-06-21 10:16:58 UTC |
| Profile Built | 2026-06-21 10:31:08 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 28 |
Full dossier details are available via our API.