# Intelligence Briefing: 190.181.91.238/32
## Executive Summary
Target IP 190.181.91.238 is classified as High Risk (Score: 80) and operates as a web server in the MicrolanOeste.net srl network (ASN 52251). Despite Argentina-registered geolocation, multiple indicators suggest potential misconfiguration or compromise. No active threat campaigns detected, but the IP is listed on 4 of 8 DNS blacklists.
## Network Ownership
- ASN: 52251 (MicrolanOeste.net srl)
- CIDR Block: 190.181.88.0/21
- Organization: MicrolanOeste.net srl
- Registration: LACNIC RIR
- Abuse Contact: Available via RDAP
## Technical Profile
- Service Purpose: Web Server
- Open Ports: TCP/443 (HTTPS)
- Server Software: lighttpd/1.4.39
- TLS Certificate: Self-signed certificate issued to Ubiquiti Networks Inc. (CN=UBNT-B4:FB:E4:A6:05:BB)
- DNS Resolution: No PTR hostnames; forward resolution count = 0
- Email Authentication: No SPF or DMARC records configured
## Risk Indicators
- Risk Score: 80 (High Risk)
- DNSBL Listings: 4 out of 8 total lists (dnsblListedCount: 4)
- Operator Score: 0.1304 (Minimal)
- Route Stability: Route not stable (isRouteStable: false)
- Threat Feeds: No active threat indicators in feeds
## Geolocation Validation
- Reported Location: Merlo, Buenos Aires, Argentina (AR)
- GeoConsensus: False (2 sources, non-consensus)
- RTT Violation: Observed 160ms vs minimum possible 231.3ms for 11,564km distance
- Conclusion: Geolocation data is implausible; target may be hosting infrastructure with spoofed location or misconfigured routing
## Neighborhood Analysis
The /24 subnet (190.181.91.0/24) shows:
- Abuse Density: 0 (low)
- Sibling IPs: 2 active neighbors
- 190.181.91.184: Risk Score 55 (Medium)
- 190.181.91.230: Risk Score 30 (Low)
- Subnet Classification: No inherited risk from peers
## Historical Observation Summary
- Total Observations: 15 signals
- Latest Activity: 2026-07-31T01:03:08 UTC
- Key Signals:
- TLS certificate and server banner confirmed
- Geolocation inferences (Argentina, 52% confidence)
- Multiple port scans detected
- Threat Persistence: 0 days (not persistently malicious)
## Intelligence Assessment
This IP functions as a web server with moderate to high risk characteristics. The combination of a high risk score, multiple DNSBL listings, and implausible geolocation data warrants monitoring. The lighttpd server version (1.4.39) may require security assessment for known vulnerabilities. While not actively engaged in known attack campaigns, the IP's presence on multiple blacklists suggests prior abuse or reputation issues.
## Recommended Actions
1. Block or rate-limit inbound connections from 190.181.91.238 at perimeter firewalls
2. Monitor for lateral movement or additional compromised IPs in the 190.181.91.0/24 subnet
3. Investigate TLS certificate configuration (self-signed cert from Ubiquiti)
4. Review historical connection logs for suspicious activity patterns
5. Consider additional monitoring on sibling IPs 190.181.91.184 and 190.181.91.230 given their risk profiles
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | MicrolanOeste.net srl |
| ASN | AS52251 |
| Network Name | 190.181.88.0 - 190.181.95.255 |
| CIDR Block | 190.181.88.0/21 |
| RIR | LACNIC |
| Country | AR |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | โ |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | lighttpd/1.4.39 |
| HTTP Title | โ |
๐ TLS Certificate
E=support@ubnt.com, CN=UBNT-B4:FB:E4:A6:05:BB, OU=Technical Support, O=Ubiquiti Networks Inc., L=San Jose, S=CA, C=US was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.| SANs | None |
| Valid From | 2017-10-17T14:22:00+00:00 |
| Valid Until | 2022-10-17T14:22:00+00:00 (expired) |
| TLS Protocol | Tls12 |
| Cipher Suite | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 1826 days |
| Serial Number | 629058B3 |
| Thumbprint | 68F6D686B331ACC8CCCFEA909344079A3F8355A4 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 20% | 5 | 6 |
| Data Coherence | Contradictory (48%) โ 3 contradiction(s) |
| Attribution | Very Low (20%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
โ Geo sources disagree on country: US, AR
โ TLS certificate claims US but primary geo says AR
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-30 04:58:49 UTC |
| Last Seen | 2026-08-01 10:25:04 UTC |
| Profile Built | 2026-07-31 01:06:37 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 19 |
Full dossier details are available via our API.