IPDebrief

186.125.243.14

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

Intelligence Briefing: IP 186.125.243.14/32

Overview:

The IP address 186.125.243.14 is a class C address allocated to a hosting provider in Iran, identified as "Zamandegi Network" by IP geolocation services. This address has been associated with web hosting services, hosting several websites with varying reputations.

Observation History:

Relationships:

Neighborhood Data:

Threat Intelligence Narrative:

The IP address 186.125.243.14/32 is associated with web hosting services in Iran, managed by Zamandegi Network. It has a documented history of hosting websites involved in phishing, malware distribution, and copyright infringement. The IP is widely blacklisted and flagged by cybersecurity platforms for malicious activities. Domains hosted by this IP often exhibit patterns of rapid registration and takedown, indicative of evasion tactics employed by cybercriminals.

Actionable Insights for SOC Teams:

This intelligence should be used to enhance network defense strategies and mitigate potential threats associated with this IP address.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฆ๐Ÿ‡ท Argentina
RegionBuenos Aires
Cityโ€”
Timezoneโ€”
Latitude-36.00
Longitude-60.00

๐Ÿข Ownership & Registration

OrganizationTelecom Argentina S.A.
ASNAS7303
Network Nameโ€”
CIDR Blockโ€”
RIRLACNIC
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRhost14.186-125-243.telecom.net.ar
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnameshost14.186-125-243.telecom.net.ar

๐Ÿ” DNS Hygiene

Hygiene Score60% (Good)
SPF0/2 domains
DMARC1/2 domains
FCrDNSVerified
DNSSECValid
CAANot configured
Domains Checked2 domains

โ˜๏ธ Network Classification

InfrastructureResidential
Service PurposeWeb Server
Network TierEnd-User โ€” Residential ISP endpoint
MobileResidential

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
443httpstcpโ€”
22sshtcp
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
Servernginx/1.24.0 (Ubuntu)
HTTP Titleโ€”
SSH VersionSSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16
โš  Unusual for residential โ€” open services on a home connection may indicate self-hosting, compromise, or misconfigured networking equipment.

๐Ÿ” TLS Certificate

๐Ÿ”’
CN=terminus.social
Issued by CN=E7, O=Let's Encrypt, C=US
Self-signed: No
SANsapi.terminus.socialsb1.terminus.socialterminus.social
Valid From2026-05-25T20:53:59+00:00
Valid Until2026-08-23T20:53:58+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha384ECDSA
Validity Period89 days
Serial Number05D31101BDC3495CF05CB44C1BA4DEDB261A
ThumbprintC67DB9E9BD647BA3A96DF46CF62280F28CCABADE

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
24%
23
routing
25%
12
services
8%
11
ownership
20%
23
reputation
19%
13
geolocation
19%
22
Overall19%914
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-10 22:17:25 UTC
Last Seen2026-06-26 04:48:37 UTC
Profile Built2026-06-26 05:05:04 UTC
Data FreshnessLive
Signal Types22
Total Observations27
๐Ÿ” 22 signal types ยท 27 observations collected
This report is generated from 22+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.