# IP Intelligence Briefing: 181.209.38.180/32
## Executive Summary
IP 181.209.38.180 is a low-risk residential/static IP with no active threat indicators. The address belongs to ASN 52361 (Ledesma Manuel Alejandro) within the lacnic registry. No open services, no blacklisting, and zero threat observations recorded.
## Technical Profile
Ownership & Registration:
- ASN: 52361
- Organization: Ledesma Manuel Alejandro
- Netname: 181.209.38.176 - 181.209.38.183
- CIDR Block: 181.209.38.176/29
- RIR: LACNIC (Latin American)
- Abuse Contact: ingenieriaip@arsat.com.ar
Geolocation:
- Profile: New York, US (US-NY)
- Historical Signals: Argentina (AR), Resistencia
- Discrepancy noted between current profile and historical geolocation data
- Geo consensus: Unconfirmed across sources
Network Role:
- Classification: Firewalled / No Services
- Open Ports: None detected
- DNS: PTR record active (180.38.209.181.in-addr.arpa), no forward resolution
- Not a CDN, proxy, VPN, Tor, or hosting provider
Threat Indicators:
- Risk Score: 25 (Low Risk)
- Blacklist Count: 0
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Abuse Confidence Score: Not applicable
## Temporal Analysis
Observation History (15 signals):
- Most recent observation: 2026-07-23
- Signal types: Geolocation (AR), Organization registration, ASN/RIR, Operator score
- Operator Score: 0.1304 (Minimal)
- No persistent threat patterns detected
- Zero threat observation count
Control Plane:
- BGP Prefix: 181.209.0.0/17
- Route Stability: Unstable
- DNSSEC: Valid
- DNSBL Listed: 1 of 8 total lists
## Neighborhood Analysis
Subnet: 181.209.38.180/24
- Neighbor Count: 0
- Risk Distribution: High: 0, Medium: 0, Low: 0
- Abuse Density: 0
- Threat Siblings: 0
- Active Siblings: 0
The immediate /24 subnet shows no active neighbors or threat siblings.
## Relationships
- Same Network: 181.209.38.176 - 181.209.38.183
- DNS Associations: 180.38.209.181.in-addr.arpa (repeated)
## Risk Assessment
Overall Risk: LOW
- Risk score of 25 falls within low-risk parameters
- No active threat indicators or malicious behavior
- No services running, suggesting passive or defensive use
- Historical data shows consistent ownership registration
## Recommendations
For SOC/Security Teams:
1. Monitor Geolocation Discrepancy: Investigate the conflict between profile (US) and historical signals (Argentina). This could indicate routing anomalies or potential spoofing.
2. Passive Monitoring: IP shows no active services, but maintain baseline traffic monitoring.
3. Subnet Context: The /24 and /29 subnets show zero abuse density—contextualizes this IP as non-malicious within its network.
4. No Immediate Action Required: No firewall rules or blocking recommended based on current risk profile.
Classification: Defensible / Low Priority Monitoring
---
*Data Source: IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Ledesma Manuel Alejandro |
| ASN | AS52361 |
| Network Name | 181.209.38.176 - 181.209.38.183 |
| CIDR Block | 181.209.38.176/29 |
| RIR | LACNIC |
| Country | AR |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | 180.38.209.181.in-addr.arpa |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 180.38.209.181.in-addr.arpa |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS52361 |
| Network Prefix | 181.209.32.0/20 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-05 23:58:08 UTC |
| Last Seen | 2026-08-27 08:10:11 UTC |
| Profile Built | 2026-08-29 05:07:09 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 21 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 181.209.38.180
Who owns the IP address 181.209.38.180?
181.209.38.180 is registered to Ledesma Manuel Alejandro. The address falls within the 181.209.38.176/29 network block. Registration is held at LACNIC.
Where is 181.209.38.180 located?
Geolocation data places 181.209.38.180 in New York. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 181.209.38.180 malicious or safe?
181.209.38.180 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 181.209.38.180?
The reverse DNS (PTR) record for 181.209.38.180 is 180.38.209.181.in-addr.arpa. This hostname is not forward-confirmed, so it should be treated as a weak signal.