# INTELLIGENCE BRIEFING: 181.237.99.142/32
Classification: Low Risk | Date Generated: 2026-07-30
---
## EXECUTIVE SUMMARY
IP address 181.237.99.142 is classified as a low-risk residential endpoint located in Pereira, Colombia. The address shows no active threat indicators, no blacklist presence, and exhibits stable ownership characteristics. No immediate defensive actions are recommended based on current intelligence.
---
## OWNERSHIP & GEOSPATIAL INTELLIGENCE
| Attribute | Value |
|---|---|
| **ASN** | 3816 |
| **Organization** | COLOMBIA TELECOMUNICACIONES S.A. ESP BIC |
| **Network Block** | 181.236.0.0/15 |
| **Country** | Colombia (CO) |
| **City/Region** | Pereira, Risaralda Department |
| **Infrastructure Type** | Residential Endpoint |
| **Provider Score** | 0 (Neutral) |
| **Authority Score** | 0 (Neutral) |
| **Risk Score** | 25/100 |
The IP is assigned to Colombia Telecomunicaciones, a major Colombian telecommunications provider. Geolocation data confirms placement in the Pereira region with consensus validation from multiple sources.
---
## THREAT INTELLIGENCE
| Indicator | Status |
|---|---|
| **Known Attacker** | No |
| **Spam Source** | No |
| **Tor Exit Node** | No |
| **Blacklist Count** | 0 |
| **Threat Campaigns** | None |
| **Abuse Confidence Score** | N/A |
| **Known Malicious Activity** | None Detected |
Threat Indicators: Empty
Campaign Correlation: No matches found
Threat Persistence: None observed
---
## NETWORK CLASSIFICATION & INFRASTRUCTURE
- Provider/CDN/Hosting: None
- VPN/Proxy: No
- Cloud Infrastructure: No
- Mobile Carrier: No
- Anycast: No
- Bogon Address: No
The IP operates as a standard residential endpoint with no special infrastructure characteristics that would typically correlate with malicious activity.
---
## OBSERVATION HISTORY
Total Observations: 11 signals
Recent Signals (2026-07-30):
- Ownership stability confirmed (no changes detected)
- Geolocation consistent (Pereira, Colombia)
- Operator score: 0.1304 (Minimal)
- Network role classification: Residential
Temporal Analysis:
- Ownership changes: 0
- Threat observation count: 0
- Persistence days: 0
- Not persistently malicious
The IP has demonstrated stable characteristics with no evidence of behavior change or escalation in threat activity.
---
## RELATIONSHIP GRAPH
Direct Relationships: 2
- Same Network: 181.236.0.0 - 181.237.255.255 (appears twice in relationship data)
No additional relationships detected with hostnames, certificates, or external organizations. The IP exists as an isolated endpoint within its assigned network block.
---
## NEIGHBORHOOD ANALYSIS
Subnet: 181.237.99.142/24
- Neighbor Count: 0
- Abuse Density: 0 (No abuse observed in subnet)
- High Risk Neighbors: 0
- Medium Risk Neighbors: 0
- Low Risk Neighbors: 0
- Threat Siblings: 0
The /24 subnet shows no abuse activity and no correlated threats from neighboring addresses.
---
## CONTROL PLANE & TECHNICAL DATA
- BGP Prefix: 181.237.96.0/20
- RPKI State: Not evaluated
- Route Changes (30d): 0
- Route Stability: Stable
- DNSSEC Valid: Yes
- DNSBL Listed: 1 of 8 lists checked
- Operator Score: 0.1304 (Minimal)
---
## RECOMMENDED ACTIONS
Risk Score: 25/100 (Low)
Status: No specific firewall rules or blocking actions recommended at this time.
Monitoring: Standard monitoring applies. No special attention required beyond routine network telemetry.
---
## SOC ANALYST NOTES
1. No Immediate Action Required โ Risk score of 25 indicates low threat posture
2. Residential Traffic Expected โ Infrastructure type is residential; traffic patterns should align with normal consumer usage
3. Geolocation Consistency โ Location data stable across observations
4. No Correlation to Known Threat Actors โ No connections to campaigns, malware, or spam operations
5. Subnet Clean โ No abuse indicators in immediate neighborhood
Priority: Low | Recommendation: Continue standard monitoring
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | COLOMBIA TELECOMUNICACIONES S.A. ESP BIC |
| ASN | AS3816 |
| Network Name | 181.236.0.0 - 181.237.255.255 |
| CIDR Block | 181.236.0.0/15 |
| RIR | LACNIC |
| Country | CO |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Residential |
| Service Purpose | Residential Endpoint |
| Network Tier | End-User โ Residential ISP endpoint |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 3 |
| routing | 20% | 1 | 1 |
| services | 28% | 2 | 2 |
| ownership | 40% | 2 | 3 |
| reputation | 20% | 1 | 2 |
| geolocation | 40% | 2 | 3 |
| Overall | 31% | 10 | 14 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-27 15:46:26 UTC |
| Last Seen | 2026-08-07 19:25:11 UTC |
| Profile Built | 2026-07-31 19:33:30 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 20 |
Full dossier details are available via our API.