# IP Intelligence Briefing: 190.124.22.225/32
Classification: Low Risk / Minimal Threat Activity
Generated: 2026-07-24
## Executive Summary
IP address 190.124.22.225 is classified as Low Risk with an overall risk score of 0. The address exhibits minimal threat indicators, no known malicious activity, and operates with a firewalled configuration showing no open services. Geolocation data presents conflicting information between current profile (Miami, US) and historical observations (Honduras), suggesting potential routing complexities or dynamic network characteristics.
## Risk Assessment
| Metric | Value | Assessment |
|---|---|---|
| Overall Risk Score | 0 | Low |
| Provider Score | 0 | Low |
| Authority Score | 0 | Low |
| Stability Score | 0 | N/A |
| Abuse Confidence Score | N/A | N/A |
| Blacklist Count | 0 | Clean |
| Operator Score | 0.1304 | Minimal |
Threat Indicators: None detected. The IP is not flagged as a known attacker, spam source, or Tor exit node. No blacklist entries identified across 8 DNSBL lists.
## Network Configuration
- Control Plane Origin: ASN 262262
- BGP Prefix: 190.124.22.0/24
- Route Stability: False (instability detected despite 0 route changes in 30 days)
- DNSSEC Validation: Valid
- Open Ports: None detected
- Service Status: Firewalled / No Services
- TLS Certificate: None
## Geolocation Analysis
Conflicting geolocation data observed across multiple data sources:
- Current Profile: United States, Florida, Miami (US-FL)
- Historical Signal 27: Honduras, Ciudad Choluteca (HN) via AlienVault OTX
- Historical Signal 7: Honduras, El Progreso, Yoro Department (HN) via MaxMind GeoLite2
The geoPlausible flag is set to false, indicating inconsistent geolocation validation across sources. This discrepancy may indicate:
- Dynamic routing or CDN edge usage
- NAT or proxy infrastructure
- Temporary IP relocation
- Data source inconsistencies
## Historical Observations
A total of 11 signal observations recorded for this IP address. Recent signals include:
- Network Role Classification: Non-residential, non-cloud, non-CDN, non-proxy infrastructure
- Geolocation Signals: Conflicting country assignments (US vs HN)
- Operator Assessment: Minimal operator score (0.1304)
- Overall Confidence: Low (0.17), with only 4 of 6 dimensions covered in recent assessments
Temporal Analysis:
- Ownership Changes: 0
- Threat Persistence Days: 0
- Threat Observation Count: 0
- Persistently Malicious: False
- Is Active Attacker: False
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: 0
## Subnet Neighborhood Analysis
Subnet: 190.124.22.0/24
- Total Siblings: 0
- Active Siblings: 0
- Threat Siblings: 0
- Abuse Density: 0
- Risk Distribution: No high/medium/low risk neighbors identified
The subnet shows no correlated malicious activity or abuse patterns in neighboring addresses.
## Relationships Graph
No relationships detected for this IP address:
- Related subnets: 0
- Associated hostnames: 0
- Connected organizations: 0
- Certificate associations: 0
## Recommended Actions
Based on the minimal risk profile and lack of threat indicators:
1. Allow Traffic: No blocking recommended for inbound/outbound traffic
2. Monitoring: Optional monitoring for geolocation consistency changes
3. Network Rules: No specific firewall rules required
4. Threat Intelligence: No enrichment or correlation actions needed
## Conclusion
IP 190.124.22.225 presents a minimal threat profile with no active malicious indicators. The primary intelligence value lies in the geolocation discrepancies between current and historical data, which warrant optional monitoring but do not indicate immediate threat activity. The subnet environment is clean with no correlated abuse patterns. No defensive actions are required at this time.
Confidence Level: Moderate (limited dimension coverage in recent assessments)
Threat Likelihood: Low
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | METRONET |
| ASN | AS262262 |
| Network Name | 190.124.20.0 - 190.124.23.255 |
| CIDR Block | 190.124.20.0/22 |
| RIR | LACNIC |
| Country | HN |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS262262 |
| Network Prefix | 190.124.22.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-07 06:27:30 UTC |
| Last Seen | 2026-08-27 02:56:47 UTC |
| Profile Built | 2026-08-29 06:22:07 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 21 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 190.124.22.225
Who owns the IP address 190.124.22.225?
190.124.22.225 is registered to METRONET. The address falls within the 190.124.20.0/22 network block. Registration is held at LACNIC.
Where is 190.124.22.225 located?
Geolocation data places 190.124.22.225 in Miami, US-FL, United States. The local time zone is America/New_York. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 190.124.22.225 malicious or safe?
190.124.22.225 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.