IP Intelligence Briefing: 184.99.134.164
Date: 2026-06-11
---
**1. Core Profile**
- Risk Score: 50 (Moderate Risk)
- Ownership: Registered to CenturyLink Communications, LLC (ASN 209, ARIN).
- Geolocation: Residential endpoint in Fargo, North Dakota, US (latitude 46.8, longitude -96.83).
- Network Role: Residential infrastructure (no CDN, cloud, or mobile indicators).
- Threat Indicators: No malicious activity detected (no blacklists, campaigns, or abuse reports).
---
**2. Observation History**
- Recent Activity:
- RTT Anomaly: 75ms observed, which is below expected minimum for 6,812km distance (minimum possible: 136.2ms).
- DNS Resolution: PTR record resolves to `184-99-134-164.frgo.qwest.net` (Qwest.net domain).
- DNSSEC: Validated, with no CAA records.
- BGP: Route stability flagged as unstable (routeChanges30d: 0, isRouteStable: false).
---
**3. Relationships & Network Context**
- Linked Entities:
- Same network: CENTURYLINK-LEGACY-QWEST-INET-128 (ASN 209).
- DNS associations: Multiple PTR records under `frgo.qwest.net`.
- Subnet Neighbors: No neighboring IPs in the /24 subnet (0 active siblings).
- Abuse Density: Subnet abuse density: 0% (no malicious siblings).
---
**4. Threat & Risk Analysis**
- Malicious Indicators:
- No indicators of botnets, spam, or known attacker activity.
- No DNSBL listings (2/8 lists checked).
- Residential Nature: Likely a legitimate residential endpoint, not a proxy, CDN, or mobile network.
---
**5. Recommended Actions**
- Firewall Rules (Sample):
- iptables: `iptables -A INPUT -s 184.99.134.164 -j DROP`
- Cloudflare WAF: Block IP with rule `{ "action": "block", "expression": "ip.src eq 184.99.134.164" }`
- Monitoring:
- Investigate RTT anomalies (potential spoofing or ISP routing quirks).
- Monitor for unexpected DNS resolution or traffic patterns.
---
**6. Conclusion**
184.99.134.164 is a legitimate residential endpoint under CenturyLink, with no immediate malicious activity detected. While its RTT metrics suggest potential spoofing or routing anomalies, no confirmed threats are present. SOC teams should treat it as low to moderate risk but remain vigilant for unusual behavior. No urgent action is required unless further suspicious activity is observed.
---
*Generated via IPDebrief intelligence tools. Use with operational judgment.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | CenturyLink Communications, LLC |
| ASN | AS209 |
| Network Name | CENTURYLINK-LEGACY-QWEST-INET-128 |
| CIDR Block | 184.96.0.0/13 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 184-99-134-164.frgo.qwest.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 184-99-134-164.frgo.qwest.net |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Residential |
| Service Purpose | Residential Endpoint |
| Network Tier | End-User β Residential ISP endpoint |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 13% | 1 | 1 |
| routing | 13% | 1 | 1 |
| services | 13% | 1 | 1 |
| ownership | 27% | 2 | 3 |
| reputation | 0% | 0 | 0 |
| geolocation | 13% | 1 | 1 |
| Overall | 13% | 6 | 7 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-26 12:51:19 UTC |
| Last Seen | 2026-06-11 04:54:37 UTC |
| Profile Built | 2026-06-11 05:13:10 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 20 |
Full dossier details are available via our API.