IPDebrief

209.141.32.143

IP Intelligence Dossier
Your IP: 216.73.217.135
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING

Target IP: 209.141.32.143/32

Classification: Moderate Risk Infrastructure Node

Date: Current Analysis Cycle

---

## EXECUTIVE SUMMARY

IP 209.141.32.143 is classified as a Moderate Risk hosting infrastructure address with a risk score of 40. The IP resides within a colocation hosting environment operated by FranTech Solutions (ASN 53667, PONYNET-04 network). No active threat indicators, known campaigns, or malicious activity were identified. The address resolves to hostname "LittleTwain" and hosts standard web and SSH services.

---

## OWNERSHIP & INFRASTRUCTURE

AttributeValue
**Organization**FranTech Solutions
**Netname**PONYNET-04
**ASN**53667
**CIDR Block**209.141.32.0/19
**RIR**ARIN
**Infrastructure Type**Colocation Hosting
**Service Purpose**Multi-Service Host
**Network Role**Hosting Provider

---

## GEOLOCATION DATA

AttributeValue
**Country**United States (US)
**Region**Nevada (NV)
**City**Las Vegas
**Geo Confidence**35%
**Geo Validation**RTT distance anomaly detected

*Note: Geo validation flagged an RTT discrepancy of 86,731 km, indicating potential geolocation data inconsistency.*

---

## NETWORK SERVICES & FINGERPRINTING

ServicePortProtocolBanner/Status
HTTP80TCPApache/2.4.41 (Ubuntu)
SSH22TCPSSH-2.0-OpenSSH_8.2p1 Ubuntu-4ubuntu0.13

Fingerprint Details:

---

## THREAT INDICATORS

Indicator TypeStatus
**Known Attacker**No
**Spam Source**No
**Tor Exit Node**No
**Blacklist Count**0
**Known Campaigns**None
**DNSBL Listed**2 of 8 lists
**Abuse Confidence Score**Not Available

---

## DNS ANALYSIS

AttributeValue
**PTR Hostname**LittleTwain
**Forward Resolution**Confirmed (1 entry)
**Email Auth**SPF: Not configured, DMARC: Not configured
**TXT Records**0

---

## NEIGHBORHOOD ANALYSIS

Subnet: 209.141.32.143/24

Abuse Density: 0.5 (Moderate)

Total Siblings: 2

Active Siblings: 2

Threat Siblings: 1

Neighbor IPRisk ScoreAuthority ScoreClassification
209.141.32.1984960Medium Risk

*Note: Neighbor 209.141.32.198 exhibits elevated risk (Score: 49) and should be monitored for correlated activity.*

---

## OBSERVATION HISTORY

Total Observations: 20

Recent Activity: June 2026

DateSignal TypeConfidenceKey Findings
2026-06-23HTTP Fingerprint80%Apache 2.4.41, HTTP/1.1
2026-06-21Campaign Analysis30%No campaigns detected
2026-06-21Geolocation35%US, 2,500km accuracy
2026-06-21Subnet Analysis40%Abuse density 0.5, mostly_clean
2026-06-21Operator Score60%Minimal (0.1304)

Temporal Indicators:

---

## RELATIONSHIP GRAPH

Total Relationships: 33

Relationship TypeCountTarget
Same Network18+PONYNET-04
DNS Association15+LittleTwain

---

## RECOMMENDED ACTIONS

Based on risk profile analysis:

1. MONITOR Neighbor IP: 209.141.32.198 (Risk Score: 49) shows elevated risk within the same /24 subnet. Correlate traffic patterns.

2. DNSBL Verification: IP appears on 2 of 8 DNSBL lists. Verify current listing status.

3. Baseline Traffic: Establish normal traffic patterns for this hosting IP given the colocation environment.

4. SSH Access Policy: Port 22 is open. Evaluate if inbound SSH access to this IP is expected for legitimate operations.

---

## CONCLUSION

IP 209.141.32.143 represents a legitimate hosting infrastructure node with moderate risk classification. No active malicious indicators were identified. The elevated abuse density (0.5) in the /24 subnet and the presence of a higher-risk neighbor (209.141.32.198) warrant ongoing monitoring. The infrastructure serves standard web and SSH services without evidence of exploitation or command-and-control activity.

Recommendation: Continue monitoring with standard procedures. No immediate blocking required unless correlation with known threat actors occurs.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionNV
CityLas Vegas
Timezoneβ€”
Latitude36.10
Longitude-115.14

🏒 Ownership & Registration

OrganizationFranTech Solutions
ASNAS53667
Network NamePONYNET-04
CIDR Block209.141.32.0/19
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRLittleTwain
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)
Forward HostnamesLittleTwain

πŸ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeMulti-Service Host
Network TierHosting β€” Infrastructure provider without advanced routing
Hosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpβ€”
22sshtcp
Closed Ports25, 443, 3389, 8080, 8443 (2 open / 7 scanned)
ServerApache/2.4.41 (Ubuntu)
HTTP Titleβ€”
SSH VersionSSH-2.0-OpenSSH_8.2p1 Ubuntu-4ubuntu0.13

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
27%
23
routing
13%
11
services
35%
24
ownership
27%
23
reputation
13%
12
geolocation
27%
23
Overall24%1016
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) β€” 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Claimed geolocation contradicts RTT physics measurement

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-06-03 00:13:10 UTC
Last Seen2026-06-29 11:39:19 UTC
Profile Built2026-06-29 11:44:37 UTC
Data FreshnessLive
Signal Types22
Total Observations23
πŸ” 22 signal types Β· 23 observations collected
This report is generated from 22+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.