# IP INTELLIGENCE BRIEFING
Target: 184.75.221.59/32
Date: Current Analysis
Risk Score: 15 (Low Risk)
Classification: Commercial Infrastructure / Low Threat
---
## EXECUTIVE SUMMARY
IP 184.75.221.59 is a low-risk commercial address registered to Amanah Tech Inc. (ASN 32489) within the 184.75.208.0/20 CIDR block. The address shows no active malicious indicators, no open services, and no recent threat activity. Geolocation signals contain minor inconsistencies that warrant monitoring but do not indicate operational compromise.
---
## OWNERSHIP AND INFRASTRUCTURE
- Organization: Amanah Tech Inc.
- ASN: 32489
- Network Block: 184.75.208.0/20
- Primary Location: Boston, Massachusetts, US (US-MA)
- Abuse Contact: Available via RDAP
- Registration: ARIN Registry
- Service Status: Firewalled / No Services Detected
- Open Ports: None identified
---
## THREAT ASSESSMENT
Current Indicators
- Risk Score: 15 (Low)
- Abuse Confidence Score: Not applicable
- Blacklist Status: Clean (0 blacklists)
- DNSBL Listed: 1 of 8 lists (minimal concern)
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
Threat Feeds
- No active threat indicators detected
- No known campaigns associated
- No certificate-based threat matches
---
## GEOLOCATION VALIDATION
Geolocation signals show conflicting data requiring analyst review:
- Primary Signal: Boston, MA, US (profile consensus)
- Secondary Signal: Toronto, ON, CA (observed via AlienVault OTX)
- Geo Plausibility: False (validation failed)
- Confidence Discrepancy: Multiple sources reporting different countries
This geographic inconsistency should be investigated during threat hunting operations, particularly if traffic patterns suggest a different origin than reported.
---
## NETWORK NEIGHBORHOOD ANALYSIS
Subnet: 184.75.221.0/24
| Metric | Value |
|---|---|
| Total Siblings | 10 |
| Abuse Density | 0% |
| High Risk | 0 |
| Medium Risk | 2 |
| Low Risk | 8 |
Notable Neighbor: 184.75.221.171 (Risk Score: 55)
- This neighbor shows elevated risk compared to the target IP.
- Consider including in monitoring scope if threat correlation is required.
---
## OBSERVATION HISTORY
Total Signals Observed: 15
Analysis Period: Recent monitoring window
Key Historical Findings:
- Multiple geolocation signals with conflicting country assignments (US/CA)
- Recent threat pulse signals detected (50 pulses associated with related entities)
- Ownership stability confirmed (0 changes observed)
- No persistent malicious behavior detected
- Last significant observation: July 30, 2026
---
## RELATIONSHIP MAPPING
Connected Entities: 2
- AMS4-NTBLK2 (Network block association - appears twice)
- No organization, certificate, or hostname relationships beyond network-level
---
## RECOMMENDED ACTIONS
Based on current risk profile (Score: 15), the following actions are recommended:
Monitoring
- Monitor: Include in standard baseline monitoring
- Geo-validate: Investigate US/CA location discrepancy
- Subnet Watch: Monitor 184.75.221.171 for elevated risk correlation
Firewall/Blocking
- Block: Not recommended (risk score below threshold)
- Rate Limit: Consider if traffic patterns warrant investigation
- Allow: Permitted through standard security controls
Intelligence
- Correlate: Cross-reference with 184.75.221.171 for potential shared infrastructure
- Threat Hunting: If this IP appears in incident logs, investigate the geographic discrepancy
---
## CONCLUSION
IP 184.75.221.59 presents minimal threat to organizational security posture. The address is part of a low-abuse-density subnet with no active malicious indicators. The primary concern is the geolocation validation failure and conflicting country signals, which should be noted for incident correlation purposes. No immediate blocking or remediation actions are warranted.
Analyst Notes: Monitor for changes in geolocation signals or emergence of threat indicators. Investigate if this IP appears in incident logs despite low-risk classification.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Amanah Tech Inc. |
| ASN | AS32489 |
| Network Name | AMS4-NTBLK2 |
| CIDR Block | 184.75.208.0/20 |
| RIR | ARIN |
| Country | Canada |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-25 08:45:04 UTC |
| Last Seen | 2026-08-01 16:33:19 UTC |
| Profile Built | 2026-07-30 03:17:35 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.