# IP Intelligence Briefing: 201.183.54.130
## Executive Summary
IP 201.183.54.130 is currently assessed as Low Risk with a risk score of 0. However, conflicting geolocation data and sparse observation history warrant monitoring. The IP shows no active services, no network infrastructure, and minimal threat indicators.
## Current Profile Assessment
- Reputation: Low Risk (Risk Score: 0)
- Provider Authority: Neutral (Provider Score: 0, Authority Score: 0)
- Stability: Inactive (Stability Score: 0)
- Network Classification: No open ports, no active services, firewalled/no services detected
- Geolocation: US (Massachusetts, Boston) per current profile data
- Ownership: No ASN, organization, or abuse contact information available
## Threat Indicators
- Blacklist Status: Not listed on any threat feeds (0 blacklists)
- Threat Classification: Not Tor exit, not known attacker, not spam source
- Campaign Association: No known campaign matches or correlated IPs
- Behavioral Signals: No honeypot hits, no enumeration strikes, no WAF violations
## Historical Observations (12 Total)
Observation history reveals significant geolocation inconsistencies:
- Recent observations (2026-07-22) indicate location in Quito, Ecuador (EC)
- Profile geolocation shows Boston, Massachusetts (US)
- DNS activity detected with domain com.ec
- One threat listing with "high" severity detected among 8 total lists
## Neighborhood Analysis
- Subnet: 201.183.54.130/24
- Abuse Density: 0%
- Neighbor Count: 0
- Risk Distribution: No neighboring IPs identified
- Network Impact: Isolated IP with no subnet-level correlation
## Relationships
- Related Entities: None detected
- Associated Hostnames: No PTR records or forward resolution
- Certificate/Domain Links: No relationships to hostnames, organizations, or certificates
## Control Plane Status
- BGP/Routing: No origin ASN or BGP prefix detected
- Route Stability: Not stable, no MOAS status
- RPKI/IRR: No consistency data available
- DNSSEC: Not validated
## Recommended Actions
No immediate blocking recommended based on current risk profile. However, the following considerations apply:
1. Monitor Geolocation Discrepancy: Investigate why the IP resolves to different countries (EC vs. US). This may indicate spoofing, proxy usage, or misconfiguration.
2. Passive Monitoring: Continue observation for any changes in threat indicators or geolocation.
3. No Active Threat: Current profile shows no active malicious behavior.
## SOC Analyst Notes
This IP appears to be either dormant, misconfigured, or potentially used for legitimate purposes with inconsistent geolocation reporting. The lack of open ports and services suggests it is not actively hosting malicious infrastructure. However, the geolocation conflict should be logged for future reference if this IP is observed in security events.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Ecuadortelecom S.A. |
| ASN | AS27738 |
| Network Name | 201.183.0.0 - 201.183.255.255 |
| CIDR Block | 201.183.0.0/16 |
| RIR | LACNIC |
| Country | EC |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | hfce-201-183-54-130.customer.claro.com.ec |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | hfce-201-183-54-130.customer.claro.com.ec |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS27738 |
| Network Prefix | 201.183.54.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-02 04:21:36 UTC |
| Last Seen | 2026-07-22 12:21:58 UTC |
| Profile Built | 2026-08-29 03:09:42 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 201.183.54.130
Who owns the IP address 201.183.54.130?
201.183.54.130 is registered to Ecuadortelecom S.A.. The address falls within the 201.183.0.0/16 network block. Registration is held at LACNIC.
Where is 201.183.54.130 located?
Geolocation data places 201.183.54.130 in Boston, US-MA, United States. The local time zone is America/New_York. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 201.183.54.130 malicious or safe?
201.183.54.130 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 201.183.54.130?
The reverse DNS (PTR) record for 201.183.54.130 is hfce-201-183-54-130.customer.claro.com.ec. This hostname is not forward-confirmed, so it should be treated as a weak signal.