IP Intelligence Briefing: 138.121.113.106
Date: 2026-06-13
---
**1. Core Profile**
- Risk Score: Low (25/100)
- Ownership:
- ISP: REFSA TELECOMUNICACIONES (AS263791)
- Location: Formosa, Argentina (Region: Formosa)
- Subnet: 138.121.112.0/22
- Threat Indicators:
- No active malware, phishing, or exploit campaigns detected.
- No DNSBL listings or known attacker associations.
- Network Role: Residential endpoint (non-cloud, non-CDN).
---
**2. Observation History**
- Recent Activity (Last 30 Days):
- 15 observations recorded, with mixed signals:
- Threat Signals: 6 inferred threats (confidence: 0.85) linked to spam or phishing campaigns.
- Geolocation: Consistent with Argentina (Formosa), though some inferred locations show discrepancies (e.g., latitude -38.42, longitude -63.62).
- DNSSEC: Valid, no spoofing detected.
- Stability: BGP route stability issues (routeChanges30d: 0, but isRouteStable: false).
---
**3. Relationships & Network Context**
- Linked Entities:
- Same /22 subnet: 138.121.112.0โ138.121.115.255.
- No direct connections to known malicious domains, organizations, or certificates.
- Subnet Abuse Density:
- Abuse Density: 0% (no malicious IPs in the subnet).
- Neighbors: No active neighbors reported (/24 subnet).
---
**4. Threat & Mitigation Analysis**
- Risk Assessment:
- Low-risk residential IP with no confirmed malicious activity.
- Potential false positives in threat signals (e.g., inferred spam campaigns).
- Recommendations:
- Monitor for unexpected DNS changes or new service activity.
- Validate geolocation anomalies (e.g., inferred coordinates outside Formosa).
- Ensure network segmentation to limit exposure from shared subnets.
---
Next Steps:
- Cross-check with internal threat feeds for any missed indicators.
- Verify ISP reputation (REFSA TELECOMUNICACIONES) for compliance with data privacy standards.
- Consider enabling DNS filtering for the subnet to mitigate potential spoofing risks.
End of Briefing
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | REFSA TELECOMUNICACIONES |
| ASN | AS263791 |
| Network Name | 138.121.112.0 - 138.121.115.255 |
| CIDR Block | 138.121.112.0/22 |
| RIR | ARIN |
| Country | AR |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Residential |
| Service Purpose | Web Server |
| Network Tier | End-User โ Residential ISP endpoint |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
๐ TLS Certificate
| SANs | pwf.dnatech.net.ar |
| Valid From | 2026-05-03T03:01:45+00:00 |
| Valid Until | 2026-08-01T03:01:44+00:00 |
| TLS Protocol | Tls12 |
| Cipher Suite | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 89 days |
| Serial Number | 05E2D02699FA896487AB1DA5E675D187D448 |
| Thumbprint | 79A0D63D16ACB857C2AA2EB757DE7A1A94A4E92E |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 27% | 2 | 3 |
| reputation | 0% | 0 | 0 |
| geolocation | 13% | 1 | 1 |
| Overall | 6% | 3 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-06-04 06:34:48 UTC |
| Last Seen | 2026-06-13 00:24:26 UTC |
| Profile Built | 2026-06-13 00:45:51 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 19 |
Full dossier details are available via our API.