Intelligence analysts observed IP 206.148.24.192 operating within the 206.148.0.0/15 block owned by Cogent Communications, LLC (ASN 7578). The profile indicated a Low Risk reputation with a risk score of 25. Reverse DNS resolution identified the hostname `e29.mel-eqxme1-cr3.globalsecurelayer.com`, associated with the domain `globalsecurelayer.com`, which maintained SPF and DMARC configurations. Geolocation data placed the system in Melbourne, Australia, though sources disagreed on country origin.
Threat feeds did not return specific indicators, campaigns, or known attacker signatures. The network role was classified as Firewalled / No Services with no open ports detected. Neighborhood analysis classified the subnet as mostly clean with low abuse density. Despite these findings, the threat actor profile was labeled Suspicious Host due to metadata inconsistencies. The overall confidence level remained Very Low. Consequently, the recommendation was to monitor the address for changes with low severity, as signal contradictions prevented definitive classification.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Cogent Communications, LLC |
| ASN | AS7578 |
| Network Name | COGENT-206-148 |
| CIDR Block | 206.148.0.0/15 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | e29.mel-eqxme1-cr3.globalsecurelayer.com |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | e29.mel-eqxme1-cr3.globalsecurelayer.com |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 13% | 1 | 1 |
| geolocation | 35% | 2 | 3 |
| Overall | 24% | 10 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-09-01 22:44:58 UTC |
| Last Seen | 2026-09-12 15:16:09 UTC |
| Profile Built | 2026-09-12 15:31:55 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 26 |
Full dossier details are available via our API.