## INTELLIGENCE BRIEFING: 181.214.83.153/32
Classification: Low Risk — Mobile Carrier Infrastructure
Overview
IP address 181.214.83.153 is assigned to mobile carrier network IPXO (ASN 14670) under LACNIC. The IP operates as a mobile carrier connection type with no open services or public-facing infrastructure. Risk assessment indicates low threat profile with no active malicious indicators.
Technical Profile
- Risk Score: 20/100 (Low Risk)
- ASN: 14670 (netutils-mnt, IPXO)
- CIDR Block: 181.214.83.0/24
- Network Role: Mobile Carrier
- DNS PTR: viper.pluraltech.com
- Status: Firewalled / No Services Detected
Geolocation Analysis
Geolocation data shows significant inconsistency. Profile indicates United States (Buffalo, NY) with coordinates 42.89°N, -78.88°W, but geolocation validation flags a critical violation: observed RTT of 36ms is below the minimum possible 122.2ms for the claimed 6108km distance from probe location. Historical signals also show Brazil (BR) designation in multiple observations. This discrepancy indicates unreliable geolocation metadata and suggests the IP should not be used for geographic-based threat correlation.
Threat Indicators
- Blacklist Count: 0
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Abuse Confidence Score: Not applicable
- DNSBL Listings: 1 of 8 lists checked
- Threat Persistence: None observed
Subnet Neighborhood
The /24 subnet (181.214.83.0/24) contains three sibling IPs with risk scores of 25 (low-medium), with authority scores ranging from 50-60. Subnet abuse density is 0, indicating no concentrated abuse activity in the immediate neighborhood.
Historical Observation
Fifteen signal observations recorded over the monitoring period show consistent organizational attribution to "netutils-mnt" with no escalation in threat indicators. Ownership has remained stable with no changes detected.
Operational Assessment
This IP represents standard mobile carrier infrastructure with no evidence of malicious activity or abuse. The mobile carrier classification, absence of open ports, and low-risk profile suggest this is legitimate network infrastructure. The geolocation inconsistencies warrant monitoring but do not indicate compromise or misconfiguration.
Recommended Actions
No immediate defensive actions required. Standard mobile carrier traffic monitoring applies. Geolocation metadata should be treated with low confidence due to validation failures.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | netutils-mnt |
| ASN | AS14670 |
| Network Name | IPXO |
| CIDR Block | 181.214.83.0/24 |
| RIR | LACNIC |
| Country | BR |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | viper.pluraltech.com |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | viper.pluraltech.com |
🔐 DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | 2/2 domains |
| DMARC | 2/2 domains |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
| Domains Checked | 2 domains |
☁️ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS14670 |
| Network Prefix | 181.214.83.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-07 00:24:06 UTC |
| Last Seen | 2026-09-29 03:07:01 UTC |
| Profile Built | 2026-09-23 13:52:04 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 26 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 181.214.83.153
Who owns the IP address 181.214.83.153?
181.214.83.153 is registered to netutils-mnt. The address falls within the 181.214.83.0/24 network block. Registration is held at LACNIC.
Where is 181.214.83.153 located?
Geolocation data places 181.214.83.153 in Buffalo, New York, United States. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 181.214.83.153 malicious or safe?
181.214.83.153 currently carries a high risk assessment, meaning indicators associated with malicious or abusive activity have been observed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 181.214.83.153?
The reverse DNS (PTR) record for 181.214.83.153 is viper.pluraltech.com. This hostname is not forward-confirmed, so it should be treated as a weak signal.
Is 181.214.83.153 a VPN, proxy, or data center address?
181.214.83.153 is classified as a mobile network based on network ownership and behavioural analysis.