Threat Intelligence Briefing for IP 186.0.142.95
*Generated via IPDebrief analysis tools*
---
**1. Core Profile**
- Risk Score: 55 (Moderate Risk)
- Ownership: No registered ASN, organization, or geolocation data.
- Network Role: Firewalled / No Services (no open ports or TLS certs detected).
- DNS:
- PTR record: `186.0.142.95.nortech.com.ar` (com.ar domain).
- No SPF/DKIM records; DNSSEC valid.
- Threat Indicators:
- Listed in 3 DNSBLs (low-severity).
- No direct malware, phishing, or campaign associations.
---
**2. Observation History**
- Recent Signals:
- DNSSEC validation confirmed.
- 3 DNSBL listings (e.g., Spamhaus, OpenBL, etc.) over the past 30 days.
- Low confidence in routing and ownership data (0.12โ0.60).
- Traceroute:
- Routed via Comcast; 7 hops timed out.
- Round-trip time (RTT) ranges from 0.4ms to 162.6ms.
---
**3. Relationships**
- DNS Association:
- Linked to `186.0.142.95.nortech.com.ar` (no abuse or threat indicators).
- No BGP/ASN Relationships: No peerings or subnet overlaps detected.
---
**4. Neighborhood Analysis**
- Subnet: `186.0.142.0/24` (abuse density: 0%).
- Neighbors:
- `186.0.142.82` (risk score: 0, authority score: 50).
- `186.0.142.98` (risk score: 0, authority score: 50).
- No malicious activity observed in sibling IPs.
---
**5. Recommendations**
1. Monitor DNS Traffic: Investigate `nortech.com.ar` for suspicious activity (e.g., C2, phishing).
2. Validate DNSBL Listings: Confirm if the IP is flagged for spam or abuse.
3. Check Ownership: Verify if the IP is registered to a legitimate entity or misconfigured infrastructure.
4. Segment Network: Ensure firewalled systems are isolated from critical assets.
---
Conclusion: The IP shows no direct malicious indicators but has ambiguous ownership and DNSBL associations. SOC teams should prioritize DNS monitoring and validate the legitimacy of the domain `nortech.com.ar`.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | MicrolanOeste.net srl |
| ASN | AS52251 |
| Network Name | 186.0.142.0 - 186.0.142.255 |
| CIDR Block | 186.0.142.0/24 |
| RIR | LACNIC |
| Country | AR |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 186.0.142.95.nortech.com.ar |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | 186.0.142.95.nortech.com.ar |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | โ |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | lighttpd/1.4.39 |
| HTTP Title | โ |
๐ TLS Certificate
E=support@ubnt.com, CN=UBNT-FC:EC:DA:9A:D3:27, OU=Technical Support, O=Ubiquiti Networks Inc., L=San Jose, S=CA, C=US was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.| SANs | None |
| Valid From | 2017-10-17T14:22:00+00:00 |
| Valid Until | 2022-10-17T14:22:00+00:00 (expired) |
| TLS Protocol | Tls12 |
| Cipher Suite | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 1826 days |
| Serial Number | B2F829AB |
| Thumbprint | BD355F76A386125C18BB556FE6D701BB1C0BE6F6 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 19% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 33% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 22% | 10 | 14 |
| Data Coherence | Contradictory (48%) โ 3 contradiction(s) |
| Attribution | Low (40%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
โ Geo sources disagree on country: US, AR
โ TLS certificate claims US but primary geo says AR
๐ Observation Timeline ๐ Fresh
| First Seen | 2026-06-05 13:13:59 UTC |
| Last Seen | 2026-06-26 08:23:29 UTC |
| Profile Built | 2026-06-25 10:45:28 UTC |
| Data Freshness | Fresh |
| Signal Types | 22 |
| Total Observations | 22 |
Full dossier details are available via our API.