# IP Intelligence Briefing: 38.100.220.204/32
## Executive Summary
IP 38.100.220.204 presents a low-risk profile with a reputation score of 25. While currently classified as Low Risk, the address exhibits DNSBL listings and geolocation inconsistencies requiring continued monitoring. The IP is hosted within the 38.100.220.0/24 subnet under ZCOMNETWORKS-AS-AP (Pakistan) with no active services detected.
## Technical Profile
- Risk Score: 25 (Low Risk)
- Country: US (New York)
- ASN: 152605 (ZCOMNETWORKS-AS-AP)
- BGP Prefix: 38.100.220.0/24
- Route Stability: Unstable (isRouteStable: false)
- Services: Firewalled / No Services Detected
- DNSBL Status: Listed on 1 of 8 DNSBLs (high severity listing recorded)
- Reverse DNS: Unresolved (PTR record not found)
## Geolocation Analysis
Geolocation data shows significant inconsistency between sources. ASN registration data identifies the origin as Pakistan (PK), while profile geolocation indicates US (New York). Historical observations confirm conflicting country assignments between Pakistan (Lahore) and United States, with geoConsensus marked as false. This discrepancy warrants validation through additional intelligence sources.
## Threat Indicators
- Blacklist Status: Listed on 8 DNSBLs with 1 high-severity entry
- Campaign Association: No known campaigns correlated
- Abuse Indicators: No active attacker status confirmed
- Historical Observations: 11 total signals recorded over monitoring period
## Neighborhood Analysis
The 38.100.220.0/24 subnet contains 12 sibling IPs with an abuse density of 0. Risk distribution shows all neighbors classified as Low Risk (scores 0-25), indicating this IP operates in isolation from broader subnet-level abuse patterns.
## Historical Activity
Signal history reveals:
- Recent DNSSEC validation on reverse zone (204.220.100.38.in-addr.arpa)
- Conflicting geolocation assignments across observations
- No evidence of escalating threat behavior or persistent malicious activity
- Threat persistence days: 0
- No ownership changes recorded
## Recommended Actions
1. Monitor: Continue monitoring for service activation or risk score escalation
2. Validate: Confirm actual geolocation through independent sources given Pakistan/US discrepancy
3. Block Criteria: Current risk profile does not warrant immediate blocking; implement at risk score threshold of 50+
4. Traffic Analysis: No active services detected; verify if traffic patterns indicate legitimate use
## Conclusion
IP 38.100.220.204 maintains a low-risk classification with no immediate threat indicators. The primary concern is geolocation inconsistency and DNSBL listings without clear attribution to malicious activity. Recommended classification: LOW RISK - PASSIVE MONITORING.
---
*Generated by IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Z COM Networks Private Limited |
| ASN | AS152605 |
| Network Name | Z-COM-CGNT-NET-1 |
| CIDR Block | 38.100.220.0/24 |
| RIR | ARIN |
| Country | Pakistan |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS152605 |
| Network Prefix | 38.100.220.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 0% | 0 | 0 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-08 00:51:24 UTC |
| Last Seen | 2026-08-29 01:38:12 UTC |
| Profile Built | 2026-08-29 01:53:20 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 20 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 38.100.220.204
Who owns the IP address 38.100.220.204?
38.100.220.204 is registered to Z COM Networks Private Limited. The address falls within the 38.100.220.0/24 network block. Registration is held at ARIN.
Where is 38.100.220.204 located?
Geolocation data places 38.100.220.204 in Lahore, Punjab, Pakistan. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 38.100.220.204 malicious or safe?
38.100.220.204 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.