IPDebrief

216.73.161.101

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

## INTELLIGENCE BRIEFING: 216.73.161.101

CLASSIFICATION: Low Risk / No Active Threat Indicators

DATE: Current as of latest observation cycle

---

EXECUTIVE SUMMARY

IP address 216.73.161.101 operates within the PFX-EXPRESSVPN infrastructure block (216.73.160.0/22) and presents minimal threat indicators. The address shows no active malicious behavior, threat associations, or blacklist listings. Network scanning indicates the host is firewalled with no services currently exposed.

---

OWNERSHIP AND INFRASTRUCTURE

Organization: Prefixx, Inc.

Netname: PFX-EXPRESSVPN

ASN: 206092

CIDR Block: 216.73.160.0/22

RIR: ARIN

Abuse Contact: Available via RDAP

The IP belongs to a VPN provider infrastructure block with multiple subnets under the same organizational control.

---

RISK ASSESSMENT

MetricValueAssessment
Overall Risk Score20/100Low Risk
Provider Score0No provider-level threats
Authority Score0No authority-level threats
Stability Score0No historical instability
Abuse ConfidenceN/ANo active abuse signals

Threat Indicators:

---

NETWORK CHARACTERISTICS

Geolocation: United States (New York region)

Note: Geolocation validation flagged as implausible (claimed distance 5,968km from probe location with 20ms RTT vs. minimum possible 119.4ms for that distance)

DNS Status:

Services: Firewalled / No Services Open

Open Ports: None detected

TLS Certificate: None

---

NETWORK NEIGHBORHOOD ANALYSIS

Subnet: 216.73.161.0/24

Classification: Clean

Abuse Density: 0 (0% of neighbors flagged as threats)

Risk Distribution:

Notable Neighbors:

The subnet demonstrates low overall abuse density with the target IP showing no inherited risk from neighboring addresses.

---

OBSERVATION HISTORY

Total Observations: 17

Recent Activity: All observations from 2026-07-29 indicate:

No temporal patterns suggest escalating threat activity.

---

RELATIONSHIP GRAPH

Direct Relationships: 4 (all Same Network)

No external network associations, hostnames, organizations, or certificates detected outside the infrastructure block.

---

CONTROL PLANE DATA

Origin ASN: 206092

BGP Prefix: 216.73.160.0/23

Route Stability: Not stable

RPKI State: Unknown

IRR Consistency: Unknown

DNSSEC Valid: Yes

DNSBL Listed: 0/8 total lists

---

TRACERoute ANALYSIS

Hop Count: 11

First Hop RTT: 0.3ms

Last Hop RTT: 22.6ms

Timed Out Hops: 2

Transit Networks: Comcast

---

RECOMMENDED ACTIONS

Firewall/Routing: No restrictive rules required. The IP presents no active threat indicators.

Monitoring: Standard monitoring practices apply. No special attention warranted.

Threat Intelligence: No alerts or threat feeds indicate malicious activity from this address.

---

CONCLUSION

IP 216.73.161.101 represents a low-risk infrastructure endpoint within a VPN provider network block. The address shows no evidence of malicious activity, threat associations, or abuse patterns. The subnet maintains a clean classification with minimal abuse density. No immediate defensive actions are required, though standard network monitoring practices should continue.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionNew York
CityNew York
Timezoneβ€”
Latitude40.72
Longitude-74.00

🏒 Ownership & Registration

OrganizationPrefixx, Inc.
ASNAS206092
Network NamePFX-EXPRESSVPN
CIDR Block216.73.160.0/22
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)

πŸ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown β€” Insufficient routing data to classify
No specific classification

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
0%
00
reputation
0%
00
geolocation
0%
00
Overall12%33
Coverage: 3/6 dimensions Β· Data sufficiency: partial
Data CoherenceMostly Consistent (80%) β€” 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Claimed geolocation contradicts RTT physics measurement

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-07-22 07:16:01 UTC
Last Seen2026-07-29 12:43:07 UTC
Profile Built2026-07-29 12:53:00 UTC
Data FreshnessLive
Signal Types19
Total Observations19
πŸ” 19 signal types Β· 19 observations collected
This report is generated from 19+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.