# IP Intelligence Briefing: 151.186.3.222/32
Date: 2026-07-27
Classification: Defensive Intelligence
Risk Assessment: Low Risk (Score: 25/100)
## Executive Summary
IP 151.186.3.222 operates within the OpenDNS NetEng team infrastructure (ASN: 36692, CIDR: 151.186.3.0/24) under the Quadra-MUM2-EDC network block. The IP is classified as a web server with standard HTTP/HTTPS services exposed. No active threat indicators or malicious activity observed.
## Technical Profile
| Attribute | Value |
|---|---|
| **ASN** | 36692 (OpenDNS NetEng team) |
| **Organization** | OpenDNS NetEng team |
| **Network Block** | 151.186.3.0/24 |
| **RIR** | RIPE |
| **Service Classification** | Web Server |
| **Open Ports** | 80 (HTTP), 443 (HTTPS) |
| **Server Banner** | Cisco Umbrella |
| **DNSSEC** | Valid |
## Geolocation Analysis
Geolocation data presents conflicting signals:
- Consensus Country: US (reported)
- Alternative Data: Mumbai, Maharashtra, India (India)
- Geo Plausibility: False (multiple geolocation sources disagree)
- Accuracy: Insufficient data for precise location
This discrepancy suggests the IP may be part of a distributed infrastructure with complex routing patterns.
## Threat Intelligence Assessment
Threat Indicators: None detected
Blacklist Status: 0/0 lists
Abuse Confidence Score: Not applicable
Known Campaigns: None
Tor Exit Node: No
Known Attacker: No
Spam Source: No
Control Plane Indicators:
- Operator Score: 0.1304 (Minimal)
- Route Stability: False
- DNSBL Listed: 1 of 8 total lists
- RPKI State: Not available
- IRR Consistency: Not available
## Neighborhood Analysis
The /24 subnet (151.186.3.0/24) shows:
- Abuse Density: 0 (Low)
- Total Siblings: 0
- Threat Siblings: 0
- High/Medium Risk Neighbors: 0
No significant abuse activity observed in neighboring IP space.
## Historical Observations
Fourteen historical observations recorded. Recent signals confirm:
- Organization: OpenDNS NetEng team (consistent)
- ASN: 36692 (consistent)
- CIDR: 151.186.3.0/24 (consistent)
- Operator Score: 0.1304 (Minimal risk)
- Geolocation: Mumbai, India (with conflicting US data)
No temporal escalation in threat signals.
## Relationship Graph
Single relationship identified:
- Same Network: Quadra-MUM2-EDC
No external entity correlations detected.
## Recommended Actions
Current Risk Profile: Low Risk
Recommended Action: No immediate action required
The IP demonstrates characteristics consistent with legitimate cloud infrastructure (Cisco Umbrella/Cloudflare). Standard monitoring applies.
## Intelligence Notes
- IP serves standard web traffic (HTTP/HTTPS)
- Server identified as Cisco Umbrella (DNS security service)
- No evidence of abuse or malicious activity
- Geolocation discrepancies warrant awareness but not immediate concern
- Subnet shows low abuse density
---
Prepared by: IPDebrief Intelligence System
Data Sources: IPDebrief Intelligence Platform
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | OpenDNS NetEng team |
| ASN | AS36692 |
| Network Name | Quadra-MUM2-EDC |
| CIDR Block | 151.186.3.0/24 |
| RIR | RIPE |
| Country | IN |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 443 | https | tcp | — |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS36692 |
| Network Prefix | 151.186.3.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 5 |
| routing | 8% | 1 | 1 |
| services | 17% | 2 | 3 |
| ownership | 23% | 2 | 4 |
| reputation | 23% | 1 | 4 |
| geolocation | 25% | 2 | 4 |
| Overall | 21% | 10 | 21 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-13 09:17:01 UTC |
| Last Seen | 2026-09-05 17:57:35 UTC |
| Profile Built | 2026-09-05 18:08:12 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 31 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 151.186.3.222
Who owns the IP address 151.186.3.222?
151.186.3.222 is registered to OpenDNS NetEng team. The address falls within the 151.186.3.0/24 network block. Registration is held at RIPE.
Where is 151.186.3.222 located?
Geolocation data places 151.186.3.222 in Mumbai, Maharashtra, India. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 151.186.3.222 malicious or safe?
151.186.3.222 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 151.186.3.222?
Responsive ports observed on 151.186.3.222 include 80, 443. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.