# IP Intelligence Briefing: 185.38.195.235/32
Classification: LOW RISK / RESIDENTIAL
Date: Current Analysis Cycle
Report Generated: IPDebrief Intelligence Platform
---
## Executive Summary
IP 185.38.195.235 presents as a low-risk residential endpoint within the 185.38.195.0/24 subnet. The address demonstrates minimal threat infrastructure characteristics with a risk score of 25/100. No active malicious campaigns or known attacker associations were identified. The subnet exhibits low abuse density (0.125), though three neighboring IPs share similar risk profiles.
---
## Ownership and Registration
| Attribute | Value |
|---|---|
| ASN | 209277 |
| Organization | APT CABLE TECHNICAL CONTACT TEAM |
| Network Name | APT_Cable_Memaliaj |
| CIDR Block | 185.38.195.0/24 |
| RIR | RIPE |
| Registration Date | Not Available |
---
## Threat Assessment
Overall Risk Score: 25/100 (Low Risk)
Threat Indicators:
- Known attacker: No
- Spam source: No
- Tor exit node: No
- Blacklist count: 0
- DNSBL listings: 1/8 total lists
Control Plane Analysis:
- Operator score: 0.1304 (Minimal)
- Route stability: Unstable (isRouteStable: false)
- Route changes (30d): 0
- RPKI state: Not determined
- IRR consistency: Not determined
---
## Network Classification
| Attribute | Value |
|---|---|
| Infrastructure Type | Residential |
| Cloud Provider | No |
| CDN | No |
| VPN | No |
| Proxy | No |
| Hosting | No |
| Mobile | No |
Network Role: Residential Endpoint with no detected open services or reverse DNS resolution.
---
## Geolocation Analysis
| Attribute | Value |
|---|---|
| Country | GB (United Kingdom) |
| City | London |
| Region | Gjirokastër County |
| Timezone | Europe/London |
| Geo Consensus | False |
| Geo Plausible | False |
Note: Geographic data shows consensus issues across multiple sources. Distance calculations indicate 1,698.2 km separation from claimed location, suggesting potential geolocation spoofing or data inconsistency.
---
## Neighborhood Analysis (185.38.195.0/24)
Subnet Risk Profile:
- Abuse Density: 0.125 (Low)
- Classification: Mostly Clean
- Total Siblings: 8
- Active Siblings: 5
- Threat Siblings: 1
Neighbor Risk Distribution:
- High Risk: 0
- Medium Risk: 0
- Low Risk: 6
Notable Neighbors (Risk Score 25):
- 185.38.195.112
- 185.38.195.232
- 185.38.195.239
---
## Historical Observation Trends
Total Observations: 17
Recent Signal Summary:
- Geolocation: Consistent geographic claims but with validation issues (ICMP blocked)
- Abuse Density: Stable at 0.125 since last observation
- Campaign Activity: None detected (cert matches: 0, banner matches: 0)
- Threat Persistence: 0 days observed
- Ownership Changes: 0 occurrences
Temporal Analysis: No evidence of persistent malicious behavior. IP has not demonstrated sustained threat activity over the observation period.
---
## Relationship Graph
Identified Relationships: 6
- Type: Same Network (APT_Cable_Memaliaj)
- External relationships (hostnames, organizations, certificates): None detected
---
## Security Recommendations
Recommended Actions:
- No immediate blocking required given low risk profile and residential classification
- Monitor if traffic patterns deviate from normal residential behavior
- Passive observation recommended for subnet-level trends
- No firewall rules suggested for iptables/nftables/Cloudflare/AWS WAF
Priority Level: LOW
Action Required: Monitor only if correlated threat activity emerges
---
## Conclusion
IP 185.38.195.235 represents a low-risk residential endpoint with no active threat indicators. The subnet environment shows minimal abuse density and stable characteristics. No immediate defensive actions are warranted. SOC teams should maintain passive observation for any behavioral changes.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | APT CABLE TECHNICAL CONTACT TEAM |
| ASN | AS209277 |
| Network Name | APT_Cable_Memaliaj |
| CIDR Block | 185.38.195.0/24 |
| RIR | RIPE |
| Country | AL |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Residential |
| Service Purpose | Residential Endpoint |
| Network Tier | End-User โ Residential ISP endpoint |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 35% | 2 | 2 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 14% | 4 | 4 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-21 12:55:07 UTC |
| Last Seen | 2026-07-29 08:47:25 UTC |
| Profile Built | 2026-07-29 09:00:03 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.