Intelligence Briefing: IP 192.129.149.155/32
Overview:
The IP address 192.129.149.155/32 has been analyzed using various cybersecurity tools and data sources to compile a comprehensive profile. This report provides a detailed overview of the IP address's characteristics, historical activity, and associated relationships.
Technical Profile:
1. Ownership and Registration:
- The IP address 192.129.149.155 is associated with [Provider Name], as indicated by WHOIS data. The registration details include a contact email and address, which are redacted for privacy.
2. Geolocation:
- The IP is geolocated in [Country], [City]. This information is derived from geolocation databases and confirms its physical presence.
3. Domain Associations:
- Reverse DNS lookup reveals the domain [example.com] associated with this IP. This domain is used for [purpose], as indicated by DNS records.
4. Historical Activity:
- Analysis of historical data shows that this IP has been active since [Date]. It has been involved in [types of traffic], with a noted increase in activity during [specific time periods].
5. Threat Intelligence:
- The IP has been flagged in [number] threat intelligence feeds for [specific threats], including [list threats such as malware distribution, phishing, or command and control activities].
6. Malware and Botnet Reports:
- This IP has been identified in [number] malware reports, indicating potential involvement in [specific malware types or botnet activities].
Behavioral Patterns:
1. Traffic Analysis:
- Network traffic analysis indicates that the IP frequently communicates with [number] external IP addresses, primarily located in [regions/countries]. This pattern suggests [possible purposes such as data exfiltration, command and control, or distributed denial of service].
2. Port Activity:
- Open ports include [list of ports], with [port numbers] being used for [specific services]. Notably, port [port number] is open, which is commonly associated with [service type].
Relationships and Associations:
1. Related IPs:
- The IP shares a subnet with [number] other IPs, indicating a possible shared infrastructure. Some of these IPs are known for [specific activities].
2. Domain and Subdomain Analysis:
- Subdomains linked to the associated domain include [list of subdomains], with [specific subdomain] being used for [purpose].
Neighborhood Data:
1. Proximity Analysis:
- Neighboring IPs have shown similar patterns of activity, including involvement in [common threats or activities].
2. Provider Infrastructure:
- Other IPs hosted by the same provider have been implicated in [related activities], suggesting a potential pattern of misuse or oversight by the provider.
Actionable Recommendations:
- Monitoring: Continuous monitoring of traffic to and from this IP is recommended, with particular attention to unusual patterns or spikes in activity.
- Blocking: Consider blocking or restricting access from this IP if it is associated with known threats or suspicious behavior.
- Alerting: Set up alerts for any new associations or activities involving this IP in threat intelligence feeds.
This intelligence briefing aims to provide SOC analysts with a clear understanding of the potential risks associated with IP 192.129.149.155/32, enabling informed decision-making and proactive defense measures.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | RackNerd LLC |
| ASN | AS36352 |
| Network Name | CC-192-129-149-128-26 |
| CIDR Block | 192.129.149.128/26 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.2p1 Debian-2 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 27% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 43% | 2 | 5 |
| Overall | 23% | 9 | 16 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-27 01:07:18 UTC |
| Last Seen | 2026-06-29 03:41:03 UTC |
| Profile Built | 2026-06-29 03:56:09 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 23 |
Full dossier details are available via our API.