IPDebrief

186.0.142.95

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

Threat Intelligence Briefing for IP 186.0.142.95

*Generated via IPDebrief analysis tools*

---

**1. Core Profile**

- PTR record: `186.0.142.95.nortech.com.ar` (com.ar domain).

- No SPF/DKIM records; DNSSEC valid.

- Listed in 3 DNSBLs (low-severity).

- No direct malware, phishing, or campaign associations.

---

**2. Observation History**

- DNSSEC validation confirmed.

- 3 DNSBL listings (e.g., Spamhaus, OpenBL, etc.) over the past 30 days.

- Low confidence in routing and ownership data (0.12โ€“0.60).

- Routed via Comcast; 7 hops timed out.

- Round-trip time (RTT) ranges from 0.4ms to 162.6ms.

---

**3. Relationships**

- Linked to `186.0.142.95.nortech.com.ar` (no abuse or threat indicators).

---

**4. Neighborhood Analysis**

- `186.0.142.82` (risk score: 0, authority score: 50).

- `186.0.142.98` (risk score: 0, authority score: 50).

---

**5. Recommendations**

1. Monitor DNS Traffic: Investigate `nortech.com.ar` for suspicious activity (e.g., C2, phishing).

2. Validate DNSBL Listings: Confirm if the IP is flagged for spam or abuse.

3. Check Ownership: Verify if the IP is registered to a legitimate entity or misconfigured infrastructure.

4. Segment Network: Ensure firewalled systems are isolated from critical assets.

---

Conclusion: The IP shows no direct malicious indicators but has ambiguous ownership and DNSBL associations. SOC teams should prioritize DNS monitoring and validate the legitimacy of the domain `nortech.com.ar`.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฆ๐Ÿ‡ท Argentina
RegionBuenos Aires
CityMerlo
Timezoneโ€”
Latitude-34.66
Longitude-58.73

๐Ÿข Ownership & Registration

OrganizationMicrolanOeste.net srl
ASNAS52251
Network Name186.0.142.0 - 186.0.142.255
CIDR Block186.0.142.0/24
RIRLACNIC
CountryAR
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR186.0.142.95.nortech.com.ar
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnames186.0.142.95.nortech.com.ar

๐Ÿ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierTier 3 โ€” Basic operator with some routing infrastructure
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
443httpstcpโ€”
Closed Ports22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned)
Serverlighttpd/1.4.39
HTTP Titleโ€”

๐Ÿ” TLS Certificate

An expired certificate for E=support@ubnt.com, CN=UBNT-FC:EC:DA:9A:D3:27, OU=Technical Support, O=Ubiquiti Networks Inc., L=San Jose, S=CA, C=US was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.
โš ๏ธ
E=support@ubnt.com, CN=UBNT-FC:EC:DA:9A:D3:27, OU=Technical Support, O=Ubiquiti Networks Inc., L=San Jose, S=CA, C=US
Issued by E=support@ubnt.com, CN=UBNT-FC:EC:DA:9A:D3:27, OU=Technical Support, O=Ubiquiti Networks Inc., L=San Jose, S=CA, C=US
Self-signed: Yes
SANsNone
Valid From2017-10-17T14:22:00+00:00
Valid Until2022-10-17T14:22:00+00:00 (expired)
TLS ProtocolTls12
Cipher SuiteTLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period1826 days
Serial NumberB2F829AB
ThumbprintBD355F76A386125C18BB556FE6D701BB1C0BE6F6

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
19%
22
routing
13%
11
services
33%
23
ownership
27%
23
reputation
13%
12
geolocation
27%
23
Overall22%1014
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceContradictory (48%) โ€” 3 contradiction(s)
AttributionLow (40%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Claimed geolocation contradicts RTT physics measurement
โš  Geo sources disagree on country: US, AR
โš  TLS certificate claims US but primary geo says AR

๐Ÿ“… Observation Timeline ๐Ÿ”„ Fresh

First Seen2026-06-05 13:13:59 UTC
Last Seen2026-06-26 08:23:29 UTC
Profile Built2026-06-25 10:45:28 UTC
Data FreshnessFresh
Signal Types22
Total Observations22
๐Ÿ” 22 signal types ยท 22 observations collected
This report is generated from 22+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.