# IP INTELLIGENCE BRIEFING: 198.20.127.144
## EXECUTIVE SUMMARY
IP address 198.20.127.144 is classified as Low Risk with a risk score of 25. The endpoint operates in a firewalled state with no active services or open ports. The IP is associated with SingleHop BV (ASN 32475), an infrastructure provider, and resolves to hostname vm350.tmdcloud.eu. The subnet 198.20.127.144/24 shows minimal abuse activity with an abuse density of 0.2 and classification of "mostly_clean."
## OWNERSHIP & INFRASTRUCTURE
- Organization: SingleHop BV
- ASN: 32475 (SINGLEHOP-BV)
- Network Prefix: 198.20.64.0/18
- Registration Date: 2012-08-24 (via ARIN)
- Geolocation: US (North Holland region, Amsterdam)
- RIR: ARIN
The endpoint is hosted on infrastructure under SingleHop BV control. BGP routing originates from ASN 32475 with a stable route assignment.
## NETWORK STATE & SERVICES
- Open Ports: None detected
- DNS PTR: vm350.tmdcloud.eu
- Forward Resolution: Confirmed to tmdcloud.eu domain
- Email Auth: SPF/DMARC not configured
- Service Purpose: Firewalled / No Services
- TLS Certificate: Not present
- HTTP Title: Not accessible
The IP shows no active web services, email authentication headers, or TLS certificates.
## THREAT INDICATORS
- Risk Score: 25 (Low)
- Abuse Confidence Score: Not available
- Blacklist Count: 0
- Known Attacker: False
- Spam Source: False
- Tor Exit Node: False
- Campaign Matches: 0
- Cert Matches: 0
- Correlated IPs: 0
No active threat indicators or known malicious campaigns are associated with this IP.
## SUBNET ANALYSIS
- Subnet: 198.20.127.144/24
- Abuse Density: 0.2
- Classification: mostly_clean
- Total Siblings: 5
- Active Siblings: 1
- Threat Siblings: 1
- Inherited Risk: 2
Neighboring IPs in the /24 subnet show similar risk profiles (score 25), with 4 neighbors identified as low-risk. Overall subnet abuse density remains minimal.
## OBSERVATION HISTORY
Signal history contains 21 observations spanning recent monitoring periods. Key observations include:
- ASN 32475 (SINGLEHOP-LLC - Internap Holding LLC, US) consistently resolved
- Subnet abuse density varied between 0.2 and 0.4
- Classification consistently marked "mostly_clean"
- No persistent malicious activity detected
- Threat observation count: 1
- Ownership changes: 0
## RELATIONSHIPS
- DNS Associations: vm350.tmdcloud.eu (primary hostname)
- Network Associations: SINGLEHOP-BV (same network)
- Multiple DNS and network relationship entries confirm infrastructure placement within SingleHop BV's network infrastructure
## ACTIONABLE RECOMMENDATIONS
Based on the low-risk profile and absence of threat indicators:
- Firewall Rules: No blocking required; traffic may be permitted
- Monitoring: Continue standard monitoring; no escalation needed
- Threat Hunt: No immediate indicators of compromise
- DNS Policy: Monitor for DNS changes; current PTR record vm350.tmdcloud.eu is established
## CONCLUSION
IP 198.20.127.144 represents standard infrastructure activity with no malicious indicators. The endpoint is firewalled, belongs to a legitimate hosting provider (SingleHop BV), and operates within a clean subnet environment. Standard defensive measures are appropriate; no blocking or escalation is warranted.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | SingleHop BV |
| ASN | AS32475 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | vm350.tmdcloud.eu |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | vm350.tmdcloud.eu |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 4 |
| routing | 19% | 1 | 2 |
| services | 8% | 1 | 1 |
| ownership | 27% | 2 | 3 |
| reputation | 26% | 1 | 4 |
| geolocation | 27% | 2 | 3 |
| Overall | 23% | 9 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-08 05:02:03 UTC |
| Last Seen | 2026-06-25 02:54:27 UTC |
| Profile Built | 2026-06-25 03:14:39 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.