# IP Intelligence Briefing: 190.86.74.238
Classification: Moderate Risk (Score: 40/100)
Date: 2026-07-29
Analyst: IPDebrief Intelligence Team
---
## Executive Summary
IP 190.86.74.238 presents a moderate risk profile with mixed threat indicators. The address is assigned to CTE S.A. de C.V. (ASN 14754) within the 190.86.0.0/16 block. While current service enumeration shows no active ports, the IP exhibits DNSBL listings and geolocation inconsistencies that warrant monitoring. No direct attack patterns or known campaign associations were identified.
---
## Ownership & Network Profile
| Attribute | Value |
|---|---|
| **Organization** | CTE S.A. de C.V. |
| **ASN** | 14754 (telgua) |
| **Network Block** | 190.86.0.0/16 |
| **RIR** | LACNIC |
| **Country** | US (reported); SV (San Salvador) in geo sources |
| **Abuse Contact** | Available via RDAP |
The IP is classified as a firewalled address with no active services detected. Service enumeration returned no open ports, TLS certificates, or HTTP titles.
---
## Threat Indicators
| Indicator | Status |
|---|---|
| Risk Score | 40 (Moderate) |
| DNSBL Listings | 2 of 8 total lists |
| Operator Score | 0.1304 (Minimal) |
| Tor Exit Node | False |
| Known Attacker | False |
| Spam Source | False |
| Blacklist Count | 0 |
| Campaign Associations | None |
Actionable Finding: The IP appears on 2 DNSBL lists despite a zero blacklist count in some feeds, indicating potential reputation inconsistencies across threat intelligence sources.
---
## Geolocation Discrepancy
The IP exhibits conflicting geographic data:
- Primary geolocation: United States (La Union)
- Secondary sources: El Salvador (San Salvador, coordinates: 13.3402, -87.8415)
- GeoPlausible: False
- GeoConsensus: False
This inconsistency suggests potential hosting infrastructure mismatches or misattribution in geolocation databases.
---
## Observation History
Twelve observations recorded on 2026-07-29:
- ASN consistently identified as AS14754 (telgua)
- Organization consistently reported as CTE S.A. de C.V.
- Abuse email: moises.ferrer@claro.com.sv
- Recent scan activity detected across multiple ports
- Threat pulses detected in one observation
Temporal Analysis: No persistent malicious behavior observed. Threat observation count: 0. Ownership changes: 0.
---
## Network Relationships & Neighborhood
- Relationships: Single association to the parent network (190.86.0.0/16)
- Neighbor Analysis: Subnet 190.86.74.238/24 shows zero neighboring IPs in the immediate scan window
- Abuse Density: 0 (no elevated abuse detected in adjacent addresses)
- Risk Distribution: No high-risk neighbors identified
---
## Control Plane Assessment
| Metric | Value |
|---|---|
| Route Stability | False |
| MOAS | False |
| DNSSEC Valid | True |
| Route Changes (30d) | 0 |
| Transit Networks | Comcast, NTT |
The control plane shows unstable routing status despite DNSSEC validation, suggesting potential BGP instability or renumbering activity.
---
## Recommended Actions
1. Monitor DNSBL activity: Two listings indicate potential reputation issues requiring ongoing monitoring
2. Verify geolocation: Investigate US vs. SV discrepancy to determine if this indicates legitimate infrastructure or spoofing
3. Passive traffic analysis: No active services detected; consider passive traffic monitoring for anomalous patterns
4. Network-level correlation: Review parent block 190.86.0.0/16 for correlated abuse patterns
---
## Conclusion
IP 190.86.74.238 represents a moderate-risk address with infrastructure inconsistencies but no active threat indicators. The DNSBL listings and geolocation conflicts are the primary concern areas. No immediate blocking is recommended; maintain monitoring and correlate with parent network activity.
Risk Level: MODERATE
Action Required: Monitor (No immediate threat)
Priority: MEDIUM
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | CTE S.A. de C.V. |
| ASN | AS14754 |
| Network Name | 190.86.0.0 - 190.86.255.255 |
| CIDR Block | 190.86.0.0/16 |
| RIR | LACNIC |
| Country | SV |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-23 20:05:30 UTC |
| Last Seen | 2026-07-29 20:00:52 UTC |
| Profile Built | 2026-07-29 20:08:56 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.