IPDebrief

38.103.170.206

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

IP INTELLIGENCE BRIEFING: 38.103.170.206/32

---

Executive Summary

IP address 38.103.170.206 presents a moderate risk profile (Risk Score: 50) with no active threat indicators currently associated with the address. The IP is geolocated to Denver, Colorado, United States and operates within the 38.103.170.0/24 BGP prefix under ASN 55688. No services are detected on the host, and the network role is classified as "Firewalled / No Services."

Risk Assessment

Geolocation & Network Context

Threat Indicators

Technical Observations

Neighborhood Analysis (38.103.170.0/24)

- 38.103.170.49: Risk Score 0, Authority Score 50

Historical Signal Observations

Relationships

Recommended Security Actions

Based on the moderate risk profile, the following blocking rules are recommended:

iptables:

```

iptables -A INPUT -s 38.103.170.206 -j DROP

```

nftables:

```

nft add rule inet filter input ip saddr 38.103.170.206 drop

```

nginx:

```

deny 38.103.170.206;

```

pfSense:

```

38.103.170.206/32

```

Cloudflare WAF:

```json

{"description":"Block 38.103.170.206 — IPDebrief risk score 50","action":"block","filter":{"expression":"ip.src eq 38.103.170.206"}}

```

AWS WAF:

```json

{"Addresses":["38.103.170.206/32"],"Description":"IPDebrief risk 50"}

```

Intelligence Narrative

IP 38.103.170.206 has been observed since at least 2026-07-25 with consistent geolocation data pointing to Denver, Colorado. The address has no active threat indicators and is not associated with known campaigns, malware distribution, or scanning activity. The subnet 38.103.170.0/24 demonstrates low abuse density with no active threat siblings, suggesting this may be a dormant or legitimately operated infrastructure endpoint.

The absence of open services, combined with the "Firewalled / No Services" classification, indicates the host is either:

1. Legitimately configured with no public-facing services

2. In a maintenance or decommissioned state

3. Protected behind enterprise firewalling

The moderate risk score (50) primarily reflects the DNSBL listing footprint (2 out of 8 lists) and route instability. No immediate blocking action is required based on threat activity alone, but monitoring is recommended given the DNSBL presence.

SOC Analyst Notes

---

*Report generated: IPDebrief Intelligence Platform*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇺🇸 United States
RegionUS-CO
CityDenver
TimezoneAmerica/Denver
Latitude39.74
Longitude-104.98

🏢 Ownership & Registration

OrganizationCogent Communications, LLC
ASNAS55688
Network NameCOGENT-A
CIDR Block38.0.0.0/8
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)

🔐 DNS Hygiene

Hygiene Score0% (None)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECNot signed
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeMulti-Service Host
Network TierUnknown — Insufficient routing data to classify
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
80httptcp—
22sshtcpBanner detected
Closed Ports25, 443, 3389, 8080, 8443 (2 open / 7 scanned)
ServerWeb server detected
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS55688
Network Prefix38.103.170.0/24
Route mappingFound
HSTSNot detected
CSPNot detected
HTTP/2Not detected

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
29%
23
routing
8%
11
services
8%
11
ownership
40%
23
reputation
8%
12
geolocation
12%
22
Overall17%912
Coverage: 6/6 dimensions · Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

📅 Observation Timeline 🔄 Live

First Seen2026-07-16 22:52:27 UTC
Last Seen2026-09-29 03:08:05 UTC
Profile Built2026-09-28 08:12:37 UTC
Data FreshnessLive
Signal Types20
Total Observations31
🔍 20 signal types · 31 observations collected
This report is generated from 20+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 38.103.170.206

Who owns the IP address 38.103.170.206?

38.103.170.206 is registered to Cogent Communications, LLC. The address falls within the 38.0.0.0/8 network block. Registration is held at ARIN.

Where is 38.103.170.206 located?

Geolocation data places 38.103.170.206 in Denver, US-CO, United States. The local time zone is America/Denver. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 38.103.170.206 malicious or safe?

38.103.170.206 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.

What ports are open on 38.103.170.206?

Responsive ports observed on 38.103.170.206 include 80, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.

🏘️ Related IP Addresses

Nearby addresses in 38.0.0.0/8

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.