# IP Intelligence Briefing: 198.98.55.60/32
## Executive Summary
IP address 198.98.55.60 is classified as Moderate Risk (Score: 50) and operates as a colocation hosting endpoint under Frantech Solutions (AS53667). The IP is currently listed on 2 of 8 DNS blacklist feeds and shows evidence of malicious activity within its /24 subnet (abuse density: 0.5). While the IP itself lacks direct threat indicators, the hosting environment and neighborhood context warrant monitoring.
---
## Technical Profile
Ownership & Infrastructure
- ASN: 53667 (Frantech Solutions)
- Organization: Frantech Solutions / Frantech/BuyVM
- Network Block: 198.98.48.0/20 (BGP: PONYNET-06)
- Geolocation: New York, NY, US
- Network Role: Colocation Hosting / Multi-Service Host
Service Fingerprint
- Open Ports: 22/tcp (SSH), 8080/tcp (HTTP-alt)
- Server Banner: SRS/5.0.212(Bee)
- DNS Resolution: No forward resolution, no PTR records
- Email Authentication: SPF, DMARC, and TXT records absent
Control Plane Status
- Route Stability: Not stable (isRouteStable: false)
- Operator Score: 0.1304 (Minimal)
- DNSBL Listed: 2/8 lists
- RPKI State: Not evaluated
- IRRC Consistency: Not evaluated
---
## Threat Assessment
Current Threat Indicators
- Blacklist Count: 0 (direct hits)
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
Risk Signals from Historical Data
- Alienvault OTX pulses detected (29 total pulses with associated threat names)
- Multiple geolocation sources indicate NY, US location
- Network classification consistently identifies as hosting provider
- Recent signal observations (2026-06-14) show ongoing monitoring activity
---
## Neighborhood Analysis
Subnet Context: 198.98.55.0/24
- Abuse Density: 0.5 (50%)
- Classification: mostly_clean
- Total Siblings: 2
- Active Siblings: 2
- Threat Siblings: 1
Neighbor IP: 198.98.55.71
- Risk Score: 40
- Authority Score: 50
- Status: Elevated risk relative to subject IP
Network Relationships:
- 19 confirmed relationships to network PONYNET-06
- Multiple Same Network relationship types detected
---
## Historical Observations
The IP has accumulated 20 historical observations with key findings:
- Operator Score: 0.1304 (Minimal) across recent signals
- Network Classification: Consistently identified as hosting infrastructure
- Geolocation: Confirmed US, New York region with 2 source consensus
- Threat Detection: Alienvault OTX has flagged activity with 29 associated pulses
Temporal Stability:
- Ownership changes: 0
- Threat persistence days: 0
- Threat observation count: 1
- Not persistently malicious
---
## Recommended Actions
Immediate Monitoring:
- Monitor port 8080 (HTTP-alt) for suspicious web traffic patterns
- Watch SSH (port 22) for unauthorized access attempts
- Track DNSBL listing status across all 8 monitored feeds
Network Defense Posture:
- Implement rate limiting on HTTP-alt port 8080
- Consider blocking or restricting SSH access based on source IP reputation
- Monitor for C2 traffic patterns on port 8080
Investigative Priorities:
- Evaluate the 2 DNSBL listings for specific blacklist rationales
- Correlate with the single threat sibling (198.98.55.71) for potential related activity
- Investigate the 198.98.48.0/20 BGP prefix for broader infrastructure risk
---
Classification: Moderate Risk - Monitor
Last Updated: 2026-06-14
Data Source: IPDebrief Intelligence Platform
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | FranTech Solutions |
| ASN | AS53667 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Multi-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| 8080 | http-alt | tcp | β |
| Closed Ports | 25, 80, 443, 3389, 8443 (2 open / 7 scanned) | ||
| Server | SRS/5.0.212(Bee) |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_8.7 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 24% | 1 | 3 |
| geolocation | 31% | 2 | 3 |
| Overall | 20% | 10 | 16 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-10 22:17:30 UTC |
| Last Seen | 2026-06-27 18:25:10 UTC |
| Profile Built | 2026-06-28 12:31:11 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 23 |
Full dossier details are available via our API.