## IP Intelligence Briefing: 185.38.195.112/32
Date: 2026-07-23
Classification: Low Risk / Residential Endpoint
Executive Summary
The IP address 185.38.195.112 is classified as a residential endpoint with a low overall risk score of 25. The IP belongs to the 185.38.195.0/24 subnet registered to APT CABLE TECHNICAL CONTACT TEAM (ASN 209277). While currently low-risk, the IP shows blacklist presence and should be monitored alongside neighboring IPs in the same /24 subnet.
Ownership and Classification
- ASN: 209277 (APT_Cable_Memaliaj)
- Organization: APT CABLE TECHNICAL CONTACT TEAM
- CIDR Block: 185.38.195.0/24
- RIR: RIPE
- Infrastructure Type: Residential Endpoint
- Geolocation: London, GB (with conflicting geolocation consensus - validation inconclusive)
Threat Indicators
- Risk Score: 25 (Low Risk)
- Blacklist Presence: Listed on 1 of 8 DNSBL lists (high severity)
- Known Campaigns: None identified
- Tor Exit: No
- Known Attacker: No
- Spam Source: No
- Abuse Confidence Score: Not applicable
Network Behavior and Services
- Open Ports: None detected
- DNS Records: No PTR hostnames, no forward resolution, no hosted domains
- TLS/HTTP: No certificates or HTTP banners detected
- Connection Type: Residential
Neighborhood Analysis
Subnet: 185.38.195.0/24
- Total Siblings: 6
- Active Siblings: 2
- Threat Siblings: 1
- Abuse Density: 0.1667 (16.67%)
- Subnet Classification: Mostly Clean
Notable Neighbors (Risk Score 25):
- 185.38.195.232
- 185.38.195.239
These neighboring IPs share the same risk profile and should be reviewed if the target IP shows suspicious activity.
Observation History
Fourteen observations recorded as of 2026-07-23. Key observations include:
- Geolocation: Validated residential status with conflicting geographic data (ICMP validation blocked)
- DNS: DNSSEC validation confirmed as valid
- Blacklist Status: High-severity listings detected in DNSBL databases
- Network Classification: Consistently classified as residential infrastructure
Risk Assessment
The IP presents minimal immediate threat but exhibits blacklist presence and operates in a subnet with 16.67% abuse density. The residential classification suggests the IP may be used for legitimate purposes but could also be leveraged for proxying or spam operations.
Recommended Actions
No specific firewall rules or blocking recommendations are generated at this time due to the low-risk classification. However, the following monitoring measures are recommended:
- Monitor for port scanning activity
- Track blacklist status changes
- Review traffic patterns if the IP appears in network logs
- Consider blocking if the subnet abuse density increases
Related Entities
- Network: APT_Cable_Memaliaj (185.38.195.0/24)
- Control Plane Origin: ASN 209277
---
*Intelligence prepared by IPDebrief Analysis System. Data sourced from network probes, DNS analysis, and threat intelligence feeds.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | APT CABLE TECHNICAL CONTACT TEAM |
| ASN | AS209277 |
| Network Name | APT_Cable_Memaliaj |
| CIDR Block | 185.38.195.0/24 |
| RIR | RIPE |
| Country | AL |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Residential |
| Service Purpose | Residential Endpoint |
| Network Tier | End-User — Residential ISP endpoint |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS209277 |
| Network Prefix | 185.38.195.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 4% | 1 | 1 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-03 16:57:57 UTC |
| Last Seen | 2026-08-22 16:38:19 UTC |
| Profile Built | 2026-08-29 10:23:28 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 20 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 185.38.195.112
Who owns the IP address 185.38.195.112?
185.38.195.112 is registered to APT CABLE TECHNICAL CONTACT TEAM. The address falls within the 185.38.195.0/24 network block. Registration is held at RIPE.
Where is 185.38.195.112 located?
Geolocation data places 185.38.195.112 in London, Gjirokastër County, United Kingdom. The local time zone is Europe/London. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 185.38.195.112 malicious or safe?
185.38.195.112 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
Is 185.38.195.112 a VPN, proxy, or data center address?
185.38.195.112 is classified as a residential network based on network ownership and behavioural analysis.