# IP Intelligence Briefing: 23.254.196.69/32
## Executive Summary
IP 23.254.196.69 presents a moderate risk profile (score: 40) and is currently classified as hosting infrastructure within a US colocation environment. The IP has no active services and no open ports detected, but appears listed on multiple DNS blacklist sources.
## Risk Assessment
- Risk Score: 40 (Moderate Risk)
- Reputation: Moderate Risk
- Infrastructure Type: Colocation Hosting
- Service Purpose: Firewalled / No Services
- Risk Classification Flags: Hosting infrastructure with no active services
## Technical Profile
- ASN: 36352
- BGP Prefix: 23.254.196.0/24
- Geolocation: United States (US)
- Route Stability: Unstable (isRouteStable: false)
- DNS PTR Records: None detected
- DNSSEC Validation: Valid
## Threat Indicators
- DNSBL Listings: 2 out of 8 total checks
- Known Attacker Status: No
- Spam Source: No
- Tor Exit Node: No
- Campaign Likelihood: Not detected
- Certificate Matches: 0
## Neighborhood Analysis
- Subnet: 23.254.196.69/24
- Abuse Density: 0
- Subnet Classification: Clean
- Threat Siblings: 0
- Active Siblings: 0
## Historical Observations
Analysis of 13 historical signals reveals:
- Multiple geolocation signals from US sources
- DNSSEC validation confirmed across observations
- Blacklist listings with high severity noted in historical data
- Organization signals indicate RackNerd LLC in some observations
- No persistent malicious behavior detected
## Observations
The IP demonstrates route instability with no active services. While the subnet shows clean classification with no abusive neighbors, the IP itself has DNSBL listings that warrant attention. No active threat campaigns or related IPs were detected.
## Recommended Actions
Based on risk assessment, the following blocking actions are recommended:
- iptables: `iptables -A INPUT -s 23.254.196.69 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 23.254.196.69 drop`
- nginx: `deny 23.254.196.69;`
- pfSense: Add 23.254.196.69/32 to block list
- Cloudflare WAF: Block IP with expression `ip.src eq 23.254.196.69`
- AWS WAF: Block 23.254.196.69/32
Assessment: This IP should be blocked at the perimeter due to DNSBL presence and moderate risk profile. No additional monitoring or investigation required given the clean subnet classification and lack of active threat indicators.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | RackNerd LLC |
| ASN | AS36352 |
| Network Name | CC-23-254-196-64-26 |
| CIDR Block | 23.254.196.64/26 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 0% | 0 | 0 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-06-18 13:32:42 UTC |
| Last Seen | 2026-06-22 02:33:12 UTC |
| Profile Built | 2026-06-22 02:41:13 UTC |
| Data Freshness | Live |
| Signal Types | 15 |
| Total Observations | 15 |
Full dossier details are available via our API.