# INTELLIGENCE BRIEFING: 190.5.21.242/32
## Executive Summary
IP address 190.5.21.242 is classified as Moderate Risk (Risk Score: 40) with no active open ports or services. The address belongs to ASN 27827 (COOP. DE PROV. DE OBRAS Y SERV. PCOS. MONJE LTDA., COSMOL), registered under LACNIC in Argentina. The IP is currently firewalled with no discoverable services.
## Ownership and Geolocation
- ASN: 27827
- Organization: COOP. DE PROV. DE OBRAS Y SERV. PCOS. MONJE LTDA.(COSMOL)
- Country: Argentina (AR)
- Region: Santa Fe
- City: Bernardo de Irigoyen
- Registration: LACNIC (Latin American and Caribbean RIR)
- PTR Record: host242.190-5-21.steel.net.ar
## Network Classification and Services
- Network Role: Firewalled / No Services
- Open Ports: None detected
- HTTP/TLS: No active web services
- DNS: Single PTR record (host242.190-5-21.steel.net.ar)
- Forward Resolution: Confirmed to net.ar TLD
- DNSBL Status: Listed on 2 of 8 DNSBL lists
## Threat Indicators
- Abuse Confidence Score: Not scored
- Known Attacker: False
- Tor Exit Node: False
- Spam Source: False
- Threat Feeds: None
- Associated Campaigns: None identified
- Known Hostnames: host242.190-5-21.steel.net.ar
## Neighborhood Analysis (190.5.21.0/24)
- Total Siblings: 20
- Active Siblings: 4
- Threat Siblings: 7
- Abuse Density: 0.35
- Classification: Mixed
- Neighbor Risk Scores: Range 40-55 (medium risk)
- Risk Distribution: 0 high, 19 medium, 0 low
- Inherited Risk Score: 14
## Historical Observations
- Total Signals: 17 observations
- Latest Data: June 26, 2026
- Subnet Classification: Mixed (abuse density 0.35)
- Threat Persistence: Not persistently malicious
- Ownership Changes: 0 recorded
## Control Plane and Routing
- Origin ASN: 27827
- BGP Prefix: 190.5.21.0/24
- Route Stability: False
- MoAS Status: False
- RPKI State: Not validated
- DNSSEC: Valid
## Geolocation Validation
- Claimed Location: Bernardo de Irigoyen, Santa Fe, AR
- Geolocation Plausibility: False
- RTT Violation: 179ms observed vs. 229.3ms minimum possible for 11,466km distance
- Probe Count: 5
- Average RTT: 200.8ms
## Recommended Actions
- Monitoring: Maintain standard monitoring for moderate-risk IP
- Blocking: Not recommended at this time due to firewalled status
- Investigation: No immediate threat indicators requiring escalation
- Neighborhood Correlation: Monitor subnet 190.5.21.0/24 for 7 threat siblings
## Threat Assessment
The IP exhibits moderate risk primarily due to DNSBL listings and mixed neighborhood classification. No active services, open ports, or known attack patterns detected. The geolocation data contains RTT validation anomalies suggesting potential data inconsistency or spoofing. No immediate defensive action required beyond standard monitoring.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | COOP. DE PROV. DE OBRAS Y SERV. PCOS. MONJE LTDA.(COSMOL) |
| ASN | AS27827 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | LACNIC |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | host242.190-5-21.steel.net.ar |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | host242.190-5-21.steel.net.ar |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 19% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 20% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 33% | 2 | 4 |
| Overall | 18% | 9 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-11 15:04:40 UTC |
| Last Seen | 2026-06-26 10:29:37 UTC |
| Profile Built | 2026-06-26 10:36:38 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.