IP INTELLIGENCE BRIEFING: 138.118.204.244
EXECUTIVE SUMMARY
IP 138.118.204.244 presents as a moderate-risk infrastructure endpoint belonging to STARTEC PROVEDOR DE INTERNET LTDA (ASN 264263), a Brazilian internet service provider. The IP is geolocated to Papanduva, Santa Catarina, Brazil, but geolocation validation shows significant discrepancies with measured RTT data suggesting unreliable location attribution. No active malicious indicators detected.
RISK ASSESSMENT
- Overall Risk Score: 50 (Moderate Risk)
- Abuse Confidence: Not applicable (no abuse indicators)
- Blacklist Status: Clean (0 blacklists)
- Threat Classification: None identified
- Campaign Association: No known campaigns correlated
OWNERSHIP AND NETWORK
- Organization: STARTEC PROVEDOR DE INTERNET LTDA
- Network Block: 138.118.204.0/22 (CIDR 255197)
- ASN: 264263
- RIR: ARIN
- Geolocation: Brazil (BR), Santa Catarina, Papanduva
- Infrastructure Type: ISP/Provider network
- Service Status: Firewalled / No Services detected
THREAT INDICATORS
- No active threat indicators observed
- Not a Tor exit node
- Not a known attacker or spam source
- No historical persistent malicious behavior
- No campaign correlations detected
NETWORK CLASSIFICATION
- Provider: Yes (ISP infrastructure)
- Cloud/CDN/VPN/Proxy: No
- Hosting: No
- Mobile/Residential: No
- Bogon/Anycast: No
- Route Stability: Unstable
DNS AND EMAIL REPUTATION
- PTR Hostname: 244.204.118.138.ip.startectelecom.net
- Forward Resolution: Failed (forward confirmed: false)
- Email Auth: SPF and DMARC records present
- DNSBL Listings: 2 out of 8 total lists (minimal operator score: 0.1304)
CONTROL PLANE ANALYSIS
- Origin ASN: 264263
- BGP Prefix: 138.118.204.0/24
- RPKI State: Not verified
- IRR Consistency: Not verified
- Route Changes (30d): 0
- MOAS Status: No
- DNSSEC: Valid
OBSERVATION HISTORY
- Total Observations: 17
- Recent Activity: Last observed 2026-07-30
- Ownership Changes: None
- Threat Persistence: None detected
- Key Signals:
- Geolocation validation violation (RTT 138ms < minimum possible 207.1ms for claimed 10,356km distance)
- Operator score rated "Minimal"
- No CDN, Tor, VPN, or proxy characteristics
NEIGHBORHOOD ANALYSIS
- Subnet: 138.118.204.244/24
- Abuse Density: 0 (clean classification)
- Total Siblings: 1
- Active Threat Siblings: 0
- Risk Distribution: No high/medium/low risk neighbors
RECOMMENDED ACTIONS
Based on risk score of 50 and minimal threat profile, the following actions are recommended:
1. Firewall Rules:
- `iptables -A INPUT -s 138.118.204.244 -j DROP`
- `nft add rule inet filter input ip saddr 138.118.204.244 drop`
2. Web Application Firewall:
- Cloudflare: Block IP with expression `ip.src eq 138.118.204.244`
- Nginx: `deny 138.118.204.244;`
3. Cloud Security:
- AWS WAF: Add `138.118.204.244/32` to block list
- Description: "IPDebrief risk 50"
INTELLIGENCE NOTES
The IP is part of a legitimate ISP infrastructure with no evidence of malicious activity. The moderate risk score (50) is likely derived from control plane characteristics and DNSBL associations rather than observed malicious behavior. The geolocation data shows validation issues that warrant monitoring but do not indicate compromise. The subnet exhibits clean neighborhood characteristics with no correlated threats.
RATING: LOW-THREAT ISP INFRASTRUCTURE
*This briefing is based on automated intelligence collection. Recommend combining with internal threat signals before implementing blocking actions.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | STARTEC PROVEDOR DE INTERNET LTDA |
| ASN | AS264263 |
| Network Name | 255197 |
| CIDR Block | 138.118.204.0/22 |
| RIR | ARIN |
| Country | BR |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | 244.204.118.138.ip.startectelecom.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 244.204.118.138.ip.startectelecom.net |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | โ |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 1 |
| reputation | 25% | 1 | 1 |
| geolocation | 35% | 2 | 2 |
| Overall | 28% | 8 | 8 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-29 16:41:15 UTC |
| Last Seen | 2026-07-31 13:31:27 UTC |
| Profile Built | 2026-07-30 22:24:56 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 19 |
Full dossier details are available via our API.