IP INTELLIGENCE BRIEFING
Target: 176.29.20.173/32
Classification: Low Risk
Date: 2026-07-30
Executive Summary
IP 176.29.20.173 was assessed as a low-risk address with no active threat indicators. The IP belongs to network JO-ZAIN (ASN: 48832) operated by LINKdotNET, registered with RIPE, and geolocated to Amman, Jordan. No malicious activity or threat associations were observed.
Network Profile
- ASN: 48832 (LINKdotNET-RIPE-MNT)
- Organization: JO-ZAIN
- CIDR Block: 176.29.0.0/16
- Geolocation: Amman, Amman Governorate, Jordan (JO)
- Coordinates: 31.96°N, 35.94°E
- Network Role: Firewalled / No Services
- Risk Score: 0
- Provider/Authority Scores: 0
Threat Assessment
The IP addressed no known threat indicators. Analysis confirmed:
- No known attacker associations
- No spam source designation
- Zero blacklist listings
- No Tor exit node status
- No known campaign affiliations
- No abuse confidence scoring
- No open ports or active services detected
Historical Observations
Fourteen signal observations were recorded, with the most recent occurring on 2026-07-30. Historical data indicates:
- No ownership changes
- No persistent malicious behavior
- Threat observation count: 0
- Signal confidence levels ranged from 0.30 to 0.85 across network classification, geolocation, and service signals
Subnet Analysis
The /24 subnet (176.29.20.0/24) showed minimal activity:
- Abuse Density: 0
- Classification: Clean
- Active Siblings: 1
- Threat Siblings: 0
- Neighbor IP: 176.29.20.229 (Risk Score: 25, Authority Score: 50)
Relationship Graph
Four relationships were identified, all linking to network entity JO-ZAIN. No hostname, organizational, or certificate associations beyond the network designation were discovered.
Recommended Actions
No firewall rules or security actions were generated due to the absence of risk indicators. The IP requires no blocking or monitoring restrictions based on current threat intelligence.
Intelligence Notes
The IP address operates as a firewalled endpoint with no accessible services. While the single neighbor IP (176.29.20.229) carries a risk score of 25, the overall subnet maintains a clean classification with zero abuse density. Continuous monitoring is not warranted at this time.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | LINKdotNET-RIPE-MNT |
| ASN | AS48832 |
| Network Name | JO-ZAIN |
| CIDR Block | 176.29.0.0/16 |
| RIR | RIPE |
| Country | JO |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 16% | 4 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-26 21:27:57 UTC |
| Last Seen | 2026-07-30 09:29:04 UTC |
| Profile Built | 2026-07-30 09:47:01 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 20 |
Full dossier details are available via our API.