IP Intelligence Briefing: 186.96.199.191/32
Date: 2026-05-30
---
**1. Profile Summary**
- Risk Score: 40 (Moderate Risk)
- Ownership: Assigned to COOPERATIVA DE ELECTRICIDAD DE PEDRO LURO (AS52490), a local utility cooperative in Argentina.
- Geolocation:
- Country: Argentina (AR)
- City: Pedro Luro
- Coordinates: -39.48° latitude, -62.68° longitude
- Distance Validation: Geo-plausibility flagged as false due to RTT anomaly (180ms vs. minimum possible 244ms for 12,203km).
- Threat Indicators: No malicious activity detected; no indicators in threat feeds or abuse reports.
---
**2. Network & Subnet Analysis**
- Subnet: 186.96.192.0/21 (16,384 IPs)
- Neighbor Risk:
- Abuse Density: 46.7% (15 neighbors analyzed).
- High-Risk Neighbors: 7 IPs (80โ85 risk score).
- Notable IPs: 186.96.199.50, 186.96.199.132, and 186.96.199.204 show elevated risk.
- Network Role: Firewalled / No Services (no open ports, no TLS/HTTP activity).
---
**3. DNS & Relationships**
- DNS Associations:
- Linked to host-186.96.199.191.luronet.com.ar (multiple DNS records).
- No domain hosting or email authentication (SPF/DKIM) detected.
- Network Relationships:
- Same subnet (186.96.192.0/21).
- No direct ties to known malicious infrastructure.
---
**4. Historical Observations**
- Recent Activity (30-Day Window):
- Geo Validation: Persistent RTT discrepancy (180ms vs. expected 244ms).
- Ownership Stability: No changes in ASN or organization.
- Threat Persistence: No observed malicious behavior over time.
---
**5. Security Recommendations**
- Firewall Rules (Sample):
- `iptables -A INPUT -s 186.96.199.191 -j DROP`
- `nft add rule inet filter input ip saddr 186.96.199.191 drop`
- Monitoring:
- Track subnet neighbors with elevated risk (e.g., 186.96.199.50, 186.96.199.132).
- Investigate geo-validation anomalies for potential spoofing or misconfigured routing.
---
Conclusion:
The IP 186.96.199.191 is associated with a local utility cooperative in Argentina and shows no direct malicious activity. However, its subnet contains a mix of low-to-moderate risk IPs, and the geo-validation anomaly warrants further investigation. No immediate action is required, but continuous monitoring is advised.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | COOPERATIVA DE ELECTRICIDAD DE PEDRO LURO |
| ASN | AS52490 |
| Network Name | 186.96.192.0 - 186.96.199.255 |
| CIDR Block | 186.96.192.0/21 |
| RIR | LACNIC |
| Country | AR |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | host-186.96.199.191.luronet.com.ar |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | host-186.96.199.191.luronet.com.ar |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 19% | 1 | 2 |
| services | 13% | 1 | 1 |
| ownership | 27% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 23% | 9 | 14 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-14 23:35:34 UTC |
| Last Seen | 2026-06-07 09:54:53 UTC |
| Profile Built | 2026-06-07 10:14:22 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 25 |
Full dossier details are available via our API.