# IP Intelligence Briefing: 192.236.222.253
Classification: Moderate Risk (Score: 65/100)
Date: Current Intelligence Cycle
## Summary
IP 192.236.222.253 is a colocation hosting endpoint located in Cupertino, California, under ASN 36352 (CENTRIOHOST-LLC.). The IP presents a moderate risk profile with evidence of DNSBL listings across 3 of 8 total lists. Network control plane data indicates route instability over the past 30 days.
## Network Context
- ASN: 36352 (CENTRIOHOST-LLC.)
- CIDR Block: 192.236.222.128/25
- Infrastructure Type: Colocation Hosting (Hostwinds)
- Geolocation: US/CA/Cupertino (geo consensus: true, geoPlausible: false)
- Neighborhood Risk: Subnet 192.236.222.0/24 shows abuse density of 0.5 with 1 identified threat sibling (192.236.222.250, Risk Score: 50)
## Service & TLS Analysis
- Open Ports: 443/TCP (HTTPS), 22/TCP (SSH - OpenSSH_9.6p1 Ubuntu-3ubuntu13.16)
- TLS Certificate: Issued by Apple Public EV Server RSA CA 1 - G1 for www.apple.com
- Server Banner: AkamaiGHost detected
- DNS Records: SPF and DMARC records configured for apple.com domains
## Threat Indicators
- DNSBL Status: Listed on 3 of 8 threat feeds
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Campaign Correlation: None detected
- Blacklist Count: 0 (Pulsedive risk: unavailable)
## Historical Activity
- Observation Count: 26 signals recorded
- Recent Activity: Multiple DNS listings observed with high severity ratings as of August 12, 2026
- Ownership Changes: None detected; stability score indicates persistent assignment
- Threat Persistence: 0 days (not persistently malicious)
## Intelligence Assessment
This IP is hosted on a colocation infrastructure with legitimate Apple TLS certificates but exhibits DNSBL listings suggesting some level of reputation degradation. The route instability flag and neighborhood abuse density (0.5) indicate this subnet may contain additional compromised endpoints. The presence of an Apple certificate on a generic hosting IP warrants verification to confirm certificate legitimacy versus potential spoofing.
## Recommended Actions
1. Monitor: Continue monitoring for DNSBL list additions/removals
2. Correlate: Investigate related IP 192.236.222.250 for additional threat indicators
3. Verify: Confirm TLS certificate authenticity on 192.236.222.253
4. Block Threshold: Consider blocking if additional high-severity threat indicators emerge
Status: Monitor β No immediate blocking required pending further threat correlation.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | CENTRIOHOST-LLC. |
| ASN | AS54290 |
| Network Name | CC-192-236-222-128-25 |
| CIDR Block | 192.236.222.128/25 |
| RIR | ARIN |
| Country | Bangladesh |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | 1/2 domains |
| DMARC | 1/2 domains |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
| Domains Checked | 2 domains |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | β |
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | AkamaiGHost |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
π TLS Certificate
| SANs | www.apple.com.cnimages.apple.comwww.apple.com |
| Valid From | 2026-07-02T22:11:57+00:00 |
| Valid Until | 2026-12-16T18:31:25+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 166 days |
| Serial Number | 6C869EE9086B3B0B1552C0AB9A6133C9 |
| Thumbprint | 8C5A350E5B7D1D54573F2417CF14ECE89F5E8E22 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 30% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 26% | 10 | 17 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-27 15:46:33 UTC |
| Last Seen | 2026-08-12 21:36:16 UTC |
| Profile Built | 2026-08-12 21:42:24 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.