IP INTELLIGENCE BRIEFING: 38.103.170.206/32
---
Executive Summary
IP address 38.103.170.206 presents a moderate risk profile (Risk Score: 50) with no active threat indicators currently associated with the address. The IP is geolocated to Denver, Colorado, United States and operates within the 38.103.170.0/24 BGP prefix under ASN 55688. No services are detected on the host, and the network role is classified as "Firewalled / No Services."
Risk Assessment
- Overall Risk Score: 50 (Moderate Risk)
- Reputation: Moderate Risk
- Provider Score: 0
- Authority Score: 0
- DNSBL Listings: 2 out of 8 total blacklists
- Abuse Confidence Score: Not applicable (no active abuse indicators)
Geolocation & Network Context
- Country: United States (US)
- Region: Colorado (US-CO)
- City: Denver
- Coordinates: 37.751, -97.822
- Timezone: America/Denver
- Origin ASN: 55688
- Route Stability: Unstable (isRouteStable: false)
- BGP Prefix: 38.103.170.0/24
- Transit Networks: Comcast
Threat Indicators
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Proxy: No
- CDN/Cloud/Hosting/VPN: No
- Mobile/Residential: No
- Bogon: No
- Anycast: No
Technical Observations
- Open Ports: None detected
- DNS Resolution: No forward resolution confirmed
- PTR Hostnames: None
- Hosted Domains: 0
- TLS Certificate: None
- HTTP Title/Server Banner: None detected
- Service Purpose: Firewalled / No Services
- Honeypot Hits: 0
- WAF Violations: 0
Neighborhood Analysis (38.103.170.0/24)
- Subnet Classification: Clean
- Abuse Density: 0
- Total Sibling IPs: 2
- Active Threat Siblings: 0
- Neighbor Analysis:
- 38.103.170.49: Risk Score 0, Authority Score 50
Historical Signal Observations
- Total Observations: 12 signals recorded
- Most Recent: 2026-07-28
- Observation Window: Multiple signals detected over 3-day period
- Operator Score: 0.1304 (Minimal)
- Geo Consensus: True
- Threat Persistence: 0 days
- Ownership Changes: 0
- Status: Not persistently malicious
Relationships
- Related Entities: None detected
- Associated Hostnames: None
- Linked Organizations: None
- Certificate Links: None
Recommended Security Actions
Based on the moderate risk profile, the following blocking rules are recommended:
iptables:
```
iptables -A INPUT -s 38.103.170.206 -j DROP
```
nftables:
```
nft add rule inet filter input ip saddr 38.103.170.206 drop
```
nginx:
```
deny 38.103.170.206;
```
pfSense:
```
38.103.170.206/32
```
Cloudflare WAF:
```json
{"description":"Block 38.103.170.206 — IPDebrief risk score 50","action":"block","filter":{"expression":"ip.src eq 38.103.170.206"}}
```
AWS WAF:
```json
{"Addresses":["38.103.170.206/32"],"Description":"IPDebrief risk 50"}
```
Intelligence Narrative
IP 38.103.170.206 has been observed since at least 2026-07-25 with consistent geolocation data pointing to Denver, Colorado. The address has no active threat indicators and is not associated with known campaigns, malware distribution, or scanning activity. The subnet 38.103.170.0/24 demonstrates low abuse density with no active threat siblings, suggesting this may be a dormant or legitimately operated infrastructure endpoint.
The absence of open services, combined with the "Firewalled / No Services" classification, indicates the host is either:
1. Legitimately configured with no public-facing services
2. In a maintenance or decommissioned state
3. Protected behind enterprise firewalling
The moderate risk score (50) primarily reflects the DNSBL listing footprint (2 out of 8 lists) and route instability. No immediate blocking action is required based on threat activity alone, but monitoring is recommended given the DNSBL presence.
SOC Analyst Notes
- Action Priority: Low-Medium
- Recommended Action: Monitor for service activation; consider blocking if business policy requires zero-risk posture
- Investigation Triggers: If this IP begins showing open ports, DNS responses, or traffic patterns inconsistent with firewalling
- Related IPs: None identified
---
*Report generated: IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Cogent Communications, LLC |
| ASN | AS55688 |
| Network Name | COGENT-A |
| CIDR Block | 38.0.0.0/8 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 0% (None) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Multi-Service Host |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 443, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS55688 |
| Network Prefix | 38.103.170.0/24 |
| Route mapping | Found |
| HSTS | Not detected |
| CSP | Not detected |
| HTTP/2 | Not detected |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 40% | 2 | 3 |
| reputation | 8% | 1 | 2 |
| geolocation | 12% | 2 | 2 |
| Overall | 17% | 9 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-16 22:52:27 UTC |
| Last Seen | 2026-09-29 03:08:05 UTC |
| Profile Built | 2026-09-28 08:12:37 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 31 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 38.103.170.206
Who owns the IP address 38.103.170.206?
38.103.170.206 is registered to Cogent Communications, LLC. The address falls within the 38.0.0.0/8 network block. Registration is held at ARIN.
Where is 38.103.170.206 located?
Geolocation data places 38.103.170.206 in Denver, US-CO, United States. The local time zone is America/Denver. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 38.103.170.206 malicious or safe?
38.103.170.206 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 38.103.170.206?
Responsive ports observed on 38.103.170.206 include 80, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.