IPDebrief

216.180.246.163

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 216.180.246.163/32

Classification: LOW RISK

Date: 2026-07-30

Analyst: IPDebrief Intelligence Team

---

## Executive Summary

IP 216.180.246.163 presents as a low-risk endpoint with no active threat indicators. The address belongs to a private customer allocation under ASN 396982 with minimal neighborhood abuse density. Historical data shows consistent low-risk behavior over the observation period. No immediate blocking or mitigation actions are recommended.

---

## Risk Assessment

MetricValueAssessment
**Risk Score**25 (1-100)Low Risk
**Reputation**Low RiskClean
**Abuse Confidence**N/ANot Applicable
**Blacklist Count**0Clean
**Known Attacker**NoBenign
**Spam Source**NoBenign
**Tor Exit Node**NoBenign

Risk Breakdown: The IP exhibits minimal threat characteristics. Risk score of 25 indicates the address falls within normal operational parameters for residential/private use cases.

---

## Network Ownership & Classification

Control Plane:

Network Role Classification:

The IP is classified as a private customer endpoint with no public-facing services exposed.

---

## Geolocation

---

## DNS & Hostname Analysis

FieldValue
**PTR Hostnames**crawler163.deepfield.net
**Forward Resolution**crawler163.deepfield.net
**Domain**deepfield.net
**Forward Confirmed**Yes
**Hosted Domains**0
**Email Auth (SPF/DMARC)**Not Configured

The hostname "crawler163.deepfield.net" suggests automated scanning or crawling activity. No email authentication records are present for this domain.

---

## Neighborhood Analysis (216.180.246.0/24)

Subnet Overview:

Risk Distribution in Subnet:

The subnet demonstrates healthy abuse density with minimal threat concentration. The target IP shares characteristics with 64 low-risk neighbors in the same /24 block.

---

## Threat Indicators

Indicator TypeStatusDetails
**Threat Feeds**EmptyNo matches
**Known Campaigns**NoneZero correlations
**Certificate Matches**0No SSL/TLS associations
**Banner Matches**0No service banners
**Correlated IPs**0No peer activity

No active threat indicators detected across all monitored feeds.

---

## Historical Observations

Observation Period: 17 signals tracked (2026-07-30)

Key Observations:

Temporal Analysis: No evidence of persistent malicious behavior. Threat observation count remains at zero.

---

## Control Plane & Routing

MetricValue
**Origin ASN**396982
**BGP Prefix**216.180.246.0/24
**Route Stable**No
**RPKI State**Not Available
**IRR Consistency**Not Available
**DNSSEC Valid**Yes
**DNSBL Listed**1 of 8 lists
**Route Changes (30d)**0

DNSSEC validation is active. One DNSBL listing detected out of 8 total lists, indicating minimal reputation impact.

---

## Recommended Actions

Current Status: No immediate security actions recommended.

Firewall Rules: None required. The IP presents no active threat profile.

Monitoring Recommendation: Continue passive observation. No active blocking or filtering measures indicated by risk assessment.

---

## Related Entities

DNS Associations:

Relationship Graph: 10 total relationships identified (DNS and network associations only).

---

## Conclusion

IP 216.180.246.163 is classified as a low-risk endpoint with no active threat indicators. The address belongs to a private customer allocation with a clean reputation profile. Historical analysis demonstrates consistent benign behavior. The subnet maintains healthy abuse density metrics with minimal threat concentration. No security actions or blocking measures are warranted at this time.

Final Risk Rating: LOW

Action Required: None

Next Review: Standard monitoring cycle

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
Regionβ€”
CityMassy
Timezoneβ€”
Latitudeβ€”
Longitudeβ€”

🏒 Ownership & Registration

OrganizationPrivate Customer
ASNAS396982
Network NameNET-216-180-246-0-24
CIDR Block216.180.246.0/24
RIRARIN
CountryFrance
Abuse Contactβ€”

🌐 DNS Intelligence

PTRcrawler163.deepfield.net
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamescrawler163.deepfield.net

πŸ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierTier 3 β€” Basic operator with some routing infrastructure
No specific classification

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
35%
22
reputation
0%
00
geolocation
0%
00
Overall18%55
Coverage: 4/6 dimensions Β· Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-07-26 03:08:59 UTC
Last Seen2026-08-13 06:44:38 UTC
Profile Built2026-07-30 06:43:45 UTC
Data FreshnessLive
Signal Types19
Total Observations19
πŸ” 19 signal types Β· 19 observations collected
This report is generated from 19+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.