# IP INTELLIGENCE BRIEFING: 138.226.239.4/32
## Executive Summary
IP address 138.226.239.4 presents a low-risk profile with a risk score of 25/100. The address is assigned to the Vertex network block (138.226.239.0/24) under ASN 213474, operated by LocalNCC-mnt. No active threat indicators were detected, and the IP shows no known malicious activity.
## Ownership and Registration
- ASN: 213474
- Organization: LocalNCC-mnt
- Network Name: Vertex
- CIDR Block: 138.226.239.0/24
- RIR: ARIN
- Abuse Contact: ban-me-please@zerolimit-servers.cool
- Geolocation: Great Britain (GB), Europe/London timezone
## Threat Assessment
- Risk Score: 25 (Low Risk)
- Abuse Confidence: Not applicable
- Blacklist Status: 0 blacklists
- Known Campaigns: None detected
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
The IP shows no evidence of malicious behavior across threat feeds. No correlation with known attack campaigns or persistent malicious activity was identified.
## Network Role and Services
- Classification: Firewalled / No Services
- Open Ports: None detected
- HTTP Services: No banners or titles detected
- TLS Certificates: None
- Email Services: No hosted domains, SPF, or DMARC records present
The IP appears to be a passive address with no active service exposure, consistent with a firewalled endpoint.
## Control Plane Analysis
- BGP Prefix: 138.226.239.0/24
- Route Stability: Unstable
- DNSBL Listings: 1 of 8 lists (12.5%)
- Operator Score: 0.1304 (Minimal)
- RPKI State: Not applicable
- DNSSEC: Valid
## Neighborhood Analysis (138.226.239.0/24)
- Subnet Classification: mostly_clean
- Abuse Density: 33.33%
- Total Sibling IPs: 3
- Active Siblings: 0
- Threat Siblings: 1
- Neighbor Risk Scores:
- 138.226.239.3: 0 (Low)
- 138.226.239.44: 25 (Low)
The /24 subnet maintains low overall risk despite moderate abuse density. One sibling IP (138.226.239.44) shares the same risk profile.
## Observation History
- Total Observations: 14 signals
- Threat Persistence: 0 days
- Ownership Changes: 0
- Persistently Malicious: No
Recent observations from July 25, 2026, confirm consistent ownership and network classification with no emerging threat patterns.
## Recommended Actions
No specific firewall rules or blocking recommendations were generated. The IP's low-risk profile and lack of active services suggest routine monitoring is sufficient.
## Intelligence Narrative
The IP 138.226.239.4 represents a benign network endpoint within the Vertex infrastructure block. The address shows no active threat indicators, no open services, and no correlation with known malicious campaigns. While the parent /24 subnet exhibits moderate abuse density (33.3%), the specific IP remains clean with zero blacklists and no threat indicators. The firewalled status and absence of hosted domains suggest this is a non-public endpoint. SOC analysts may monitor the IP for any behavioral changes, but immediate action is not warranted.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | LocalNCC-mnt |
| ASN | AS213474 |
| Network Name | Vertex |
| CIDR Block | 138.226.239.0/24 |
| RIR | ARIN |
| Country | VU |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS213474 |
| Network Prefix | 138.226.239.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 25% | 1 | 1 |
| Overall | 22% | 6 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-09 13:31:14 UTC |
| Last Seen | 2026-08-27 04:23:47 UTC |
| Profile Built | 2026-08-29 06:00:37 UTC |
| Data Freshness | Live |
| Signal Types | 15 |
| Total Observations | 17 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 138.226.239.4
Who owns the IP address 138.226.239.4?
138.226.239.4 is registered to LocalNCC-mnt. The address falls within the 138.226.239.0/24 network block. Registration is held at ARIN.
Where is 138.226.239.4 located?
Geolocation data places 138.226.239.4 in United Kingdom. The local time zone is Europe/London. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 138.226.239.4 malicious or safe?
138.226.239.4 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.