# IP INTELLIGENCE BRIEFING: 148.101.196.130/32
## Executive Summary
IP 148.101.196.130 is a moderate-risk residential/ISP address assigned to Compañía Dominicana de Teléfonos S. A. (AS6400) in Santiago de los Caballeros, Dominican Republic. The IP shows no active threat indicators despite moderate risk scoring, with DNSBL listings on 2 of 8 reputation feeds.
## Technical Profile
Risk Classification: Moderate Risk (Score: 50/100)
Network Owner: Compañía Dominicana de Teléfonos S. A. (AS6400)
CIDR Block: 148.101.0.0/16
Geolocation: Santiago de los Caballeros, Santiago Province, DO
DNS Resolution: 130.196.101.148.d.dyn.claro.net.do (Dynamic Claro hostname)
Service Status: Firewalled / No Services Detected
## Threat Indicators
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 2/8 DNSBL listings
- Threat Feeds: None populated
- Campaign Correlation: None identified
DNSBL Context: Two DNSBL listings detected but no associated threat campaigns or campaign likelihood scoring.
## Geolocation Validation
Status: GEOLOCATION INVALIDATION DETECTED
Claimed Location: Santiago, DO (19.49°N, 70.74°W)
Observed RTT: 73ms average
Minimum Possible RTT: 149.1ms for claimed distance (7,454 km)
Conclusion: Geolocation data is implausible; RTT violation indicates spoofed or misreported location.
## Network Context
Subnet Analysis: 148.101.196.0/24
Abuse Density: 0%
Siblings with Activity: None
Related Networks: 148.101.0.0/16 (same provider network)
DNS Associations: Dynamic Claro.net.do hostname (130.196.101.148.d.dyn.claro.net.do)
## Observation History
Total Observations: 14 signals
Recent Activity: Last observed 2026-07-31
Threat Persistence: Not persistently malicious
Ownership Stability: No ownership changes detected
## Recommended Actions
SOC Analysis: Monitor for correlation with known threats; current profile indicates legitimate ISP infrastructure.
Firewall: No immediate blocking recommendedβno active threat indicators.
DNSBL Investigation: Investigate the 2 DNSBL listings for potential reputation issues.
Geolocation: Treat claimed location as unreliable; actual operational location unknown.
## Risk Assessment
This IP represents legitimate ISP infrastructure with moderate baseline risk scoring. The absence of active threat indicators (no known campaigns, no Tor exit, no spam attribution) suggests the IP is not actively malicious. However, the DNSBL listings warrant monitoring, and the geolocation invalidation indicates potential spoofing or misattribution in infrastructure data.
Recommendation: Monitor for changes in threat indicators; no immediate blocking required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Compañía Dominicana de Teléfonos S. A. |
| ASN | AS6400 |
| Network Name | 148.101.0.0 - 148.101.255.255 |
| CIDR Block | 148.101.0.0/16 |
| RIR | ARIN |
| Country | DO |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 130.196.101.148.d.dyn.claro.net.do |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 130.196.101.148.d.dyn.claro.net.do |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | Apache |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | 2021-10-04T17:31:03+00:00 |
| Valid Until | 2031-10-05T17:31:03+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 3653 days |
| Serial Number | 6F874F99 |
| Thumbprint | B9AC3F926C174D4476C68AA28AE898A13AF26770 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 16% | 4 | 5 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-30 23:19:55 UTC |
| Last Seen | 2026-08-01 22:41:20 UTC |
| Profile Built | 2026-07-31 04:38:16 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.