# IP Intelligence Briefing: 185.198.240.34/32
## Executive Summary
Target IP 185.198.240.34 presents a Low Risk profile with a risk score of 25. The address is associated with VPN Consumer infrastructure in the United States (New Jersey). While current threat indicators are absent, geographic signal inconsistencies and RTT violations warrant monitoring. No immediate blocking is recommended based on available intelligence.
## Risk Assessment
| Metric | Value |
|---|---|
| Risk Score | 25 (Low Risk) |
| Provider Score | 0 |
| Authority Score | 0 |
| Stability Score | 0 |
| Abuse Confidence | Not applicable |
| Classification | Firewalled / No Services |
## Geographic & Infrastructure Data
- Location: Trenton, New Jersey, United States (US/NJ)
- Coordinates: 40.22°N, 74.74°W
- ASN: 62240 (Comcast)
- BGP Prefix: 185.198.240.0/24
- RIR Registry: RIPE
- DNSBL Listings: 1 of 8 total lists
## Threat Indicators
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Malware Campaign Affiliation: None identified
- Blacklist Count: 0
- Threat Feeds: Empty
## Observed Anomalies
1. Geographic Inconsistencies: Signal history shows conflicting geolocation dataβsome probes indicated Netherlands (NL, 52.13°N, 5.29°W) while primary consensus places the IP in Trenton, NJ. Confidence scores for conflicting signals ranged from 0.30 to 0.95.
2. RTT Violation: One signal observed RTT of 24.6ms against a claimed distance of 6,051km, which violates physical transmission constraints (minimum possible RTT: 121.0ms).
3. DNSBL Presence: Single DNSBL listing detected among 8 total checks.
4. Subnet Activity: Neighborhood 185.198.240.0/24 shows moderate activity with 120 total sibling IPs, 56 active, and 11 identified threat siblings. Abuse density rated 0.0917 ("mostly_clean").
## Network Behavior
- Open Ports: None detected
- TLS Certificate: Not present
- HTTP Title: Not present
- Service Purpose: Firewalled / No Services
- Connection Type: Residential (per classification)
## Control Plane
- Route Stability: False
- RPKI State: Not validated
- IRR Consistency: Not validated
- Route Changes (30d): 0
- DNSSEC Valid: True
## Historical Observations
Total of 13 observations recorded. Key signals include:
- Org identification: "VPN Consumer New Jersey, United States of America"
- Abuse contact: abuse-reports@vpnconsumer.com
- CIDR block: 185.198.240.0/25
- Geographic inconsistencies observed across multiple probe types
## Recommended Actions
No specific firewall rules or blocking recommendations are generated based on the low-risk profile. The following actions are advised:
1. Monitor: Continue observing the IP for changes in threat indicators, particularly given the geographic inconsistencies.
2. Correlate: Check if traffic from this IP correlates with other IPs in the 185.198.240.0/24 subnet showing elevated risk.
3. Allow with Logging: Permitted traffic may be allowed but should be logged for forensic purposes.
4. No Immediate Block: Blocking not recommended without additional corroborating evidence.
## Intelligence Confidence
- Geolocation Confidence: Moderate (inconsistent signals)
- Ownership Confidence: Moderate (VPN consumer infrastructure)
- Threat Confidence: Low (no active indicators)
---
*This briefing is based on IPDebrief intelligence platform data. All assessments are factual and derived from observed signals. SOC teams should correlate with internal threat intelligence before taking action.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | VPN Consumer New Jersey, United States of America |
| ASN | AS62240 |
| Network Name | US-NJ-185-198-240-0 |
| CIDR Block | 185.198.240.0/25 |
| RIR | RIPE |
| Country | US |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-23 13:56:36 UTC |
| Last Seen | 2026-07-29 18:37:16 UTC |
| Profile Built | 2026-07-29 18:51:55 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.