# IP Intelligence Briefing: 186.124.218.93/32
## Executive Summary
IP address 186.124.218.93 is a residential mobile endpoint assigned to Telecom Argentina S.A. (AS7303) located in Sumampa, Santiago del Estero, Argentina. The IP registers a moderate risk score of 55/100 and demonstrates no confirmed malicious activity. However, the subnet exhibits elevated abuse density, warranting increased monitoring.
## Network Ownership and Classification
- Organization: Telecom Argentina S.A. (AS7303, LACNIC)
- Network: 186.124.0.0/15 (BGP prefix: 186.124.0.0/15)
- Geolocation: Argentina (AR), Sumampa, Santiago del Estero
- Classification: Residential/Mobile Endpoint
- Mobile Carrier: Telecom Argentina S.A. (MCC: 722, MNC: 340, LTE/5G technology)
- DNS PTR: host93.186-124-218.telecom.net.ar
- Forward Resolution: Confirmed via net.ar domain
## Risk Assessment
The IP maintains a moderate risk profile (55/100) with the following characteristics:
- Threat Indicators: None detected. No confirmed attacks, campaigns, spam source, or Tor exit node activity.
- Blacklist Status: 0 confirmed blacklists; control plane indicates 3 DNSBL listings out of 8 total lists.
- Route Stability: Stable BGP routing with no route changes in the past 30 days.
- ISP Reputation: Operator score of 0.2609 (Basic classification).
## Neighborhood Analysis
The /24 subnet (186.124.218.0/24) demonstrates mixed abuse characteristics:
- Abuse Density: 23.33% (0.2333)
- Subnet Classification: Mixed
- Total Siblings: 30 IPs
- Active Siblings: 11
- Threat Siblings: 7
High-Risk Neighbors (Risk Score โฅ70):
- 186.124.218.24 (80), 186.124.218.26 (70), 186.124.218.39 (70), 186.124.218.120 (80), 186.124.218.140 (70), 186.124.218.151 (70), 186.124.218.199 (80), 186.124.218.214 (80), 186.124.218.229 (80), 186.124.218.231 (70), 186.124.218.232 (70), 186.124.218.253 (80)
## Observed Activity History
Analysis of 24 historical observations indicates:
- Recent signals from June 2026 confirm network ownership and BGP routing
- One observation flagged abuse density of 0.2333 with mixed subnet classification
- No persistent malicious behavior detected (threat persistence: 0 days)
## Recommended Actions
Immediate Monitoring:
- Increase logging verbosity for all traffic from this IP
- Review recent activity patterns and connection attempts
Firewall/Blocking Recommendations:
- iptables: `iptables -A INPUT -s 186.124.218.93 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 186.124.218.93 drop`
- nginx: `deny 186.124.218.93;`
- pfSense: 186.124.218.93/32
- Cloudflare WAF: Block with expression `ip.src eq 186.124.218.93`
- AWS WAF: Add CIDR `186.124.218.93/32` to blocklist
## Assessment
This IP represents a residential mobile endpoint with moderate risk characteristics. While no active malicious indicators were detected, the subnet's 23.33% abuse density and presence of multiple high-risk neighbors suggest elevated threat activity in the vicinity. SOC teams should implement enhanced logging and monitor for any pattern changes, particularly given the residential/mobile nature of the endpoint which is commonly associated with compromised devices in botnet activities.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Telecom Argentina S.A. |
| ASN | AS7303 |
| Network Name | โ |
| CIDR Block | 186.124.0.0/15 |
| RIR | LACNIC |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | host93.186-124-218.telecom.net.ar |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | host93.186-124-218.telecom.net.ar |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Residential |
| Service Purpose | Residential Endpoint |
| Network Tier | End-User โ Residential ISP endpoint |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 40% | 2 | 3 |
| services | 18% | 2 | 2 |
| ownership | 29% | 3 | 4 |
| reputation | 17% | 1 | 2 |
| geolocation | 32% | 2 | 3 |
| Overall | 28% | 12 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:01 UTC |
| Last Seen | 2026-06-23 01:26:15 UTC |
| Profile Built | 2026-06-23 01:33:32 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 25 |
Full dossier details are available via our API.