## IP Intelligence Briefing: 186.1.224.42/32
Executive Summary
IP address 186.1.224.42 is classified as Moderate Risk (Score: 55). The address belongs to MicrolanOeste.net srl (ASN 52251) in Argentina and is currently firewalled with no active services. While the individual IP shows no direct threat indicators, the /24 subnet exhibits elevated abuse density (0.286) with multiple high-risk sibling addresses.
Ownership & Geolocation
- Organization: MicrolanOeste.net srl
- ASN: 52251 (lacnic RIR)
- Network Block: 186.1.224.0 - 186.1.224.255 (/24)
- Location: Pilar, Buenos Aires, Argentina (Lat: -34.48, Long: -58.93)
- Abuse Contact: Available via RDAP
Network Services & DNS
- Service Status: Firewalled / No Services
- Open Ports: None detected
- Reverse DNS: 186.1.224.42.nortech.com.ar (forward confirmed)
- Hosted Domains: 1 (186.1.224.42.nortech.com.ar)
- Email Authentication: No SPF or DMARC records configured
Threat Indicators
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0 (0 lists)
- Campaign Association: None detected
- DNSBL Listings: 3 of 8 total lists
Control Plane Analysis
- Route Stability: Unstable (isRouteStable: false)
- Operator Score: 0.2609 (Basic classification)
- RPKI Status: Not validated
- BGP Prefix: 186.1.224.0/24
Subnet Neighborhood Assessment
The /24 subnet contains 7 sibling IPs with an abuse density of 0.286. Risk distribution shows:
- High Risk (2): 186.1.224.45 (80), 186.1.224.88 (80)
- Medium Risk (4): 186.1.224.39, 186.1.224.47, 186.1.224.71, 186.1.224.86 (all 55)
- Low Risk (1): 186.1.224.77 (30)
Observation History
- Total Signals: 15 observations
- Recent Activity: Observed on 2026-07-22
- Ownership Changes: 0
- Threat Persistence: 0 days
- Persistently Malicious: No
Relationships
Three relationships identified:
1. DNS Association: 186.1.224.42.nortech.com.ar
2. Same Network: 186.1.224.0 - 186.1.224.255
3. DNS Association: 186.1.224.42.nortech.com.ar
Recommended Security Actions
1. Monitor Subnet: Flag 186.1.224.42 and high-risk siblings (186.1.224.45, 186.1.224.88) for enhanced logging
2. Firewall Rule: No immediate block recommended; moderate risk with no active services
3. DNS Monitoring: Track nortech.com.ar domain for additional C2 or phishing indicators
4. Subnet Context: Investigate 186.1.224.45 and 186.1.224.88 as primary threats within the subnet
5. Email Policy: No SPF/DMARC configured—monitor for spoofing if domain is abused
Risk Assessment
The IP presents moderate risk due to subnet-level abuse patterns rather than individual threat activity. No direct malicious indicators were observed. The primary concern is the elevated risk of sibling addresses within the /24 block, which may indicate shared infrastructure or coordinated activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | MicrolanOeste.net srl |
| ASN | AS52251 |
| Network Name | 186.1.224.0 - 186.1.224.255 |
| CIDR Block | 186.1.224.0/24 |
| RIR | LACNIC |
| Country | AR |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | 186.1.224.42.nortech.com.ar |
| Forward Confirmed | Yes — FCrDNS verified |
| Forward Hostnames | 186.1.224.42.nortech.com.ar |
🔐 DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 — Basic operator with some routing infrastructure |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS52251 |
| Network Prefix | 186.1.224.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 8% | 2 | 2 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-02 04:21:23 UTC |
| Last Seen | 2026-08-24 13:13:22 UTC |
| Profile Built | 2026-08-29 09:48:31 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 186.1.224.42
Who owns the IP address 186.1.224.42?
186.1.224.42 is registered to MicrolanOeste.net srl. The address falls within the 186.1.224.0/24 network block. Registration is held at LACNIC.
Where is 186.1.224.42 located?
Geolocation data places 186.1.224.42 in Pilar, Buenos Aires, Argentina. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 186.1.224.42 malicious or safe?
186.1.224.42 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 186.1.224.42?
The reverse DNS (PTR) record for 186.1.224.42 is 186.1.224.42.nortech.com.ar. This hostname is forward-confirmed, meaning it resolves back to the same address.