## INTELLIGENCE BRIEFING: IP 38.172.162.90/32
Date: 2026-07-31
Classification: Low Risk / Defensive Context
Analysis Priority: Standard
---
EXECUTIVE SUMMARY
IP 38.172.162.90 is classified as Low Risk (Risk Score: 25) with no active threat indicators. The address belongs to a Venezuelan network infrastructure provider (RED SERVITEL, CA) with no known malicious activity. The IP is currently firewalled with no open services and demonstrates a clean neighborhood profile.
---
OWNERSHIP & GEOLOCATION
| Attribute | Value |
|---|---|
| **ASN** | 270026 |
| **Organization** | RED SERVITEL, CA |
| **Network Name** | RED-SERVITEL-CGNT-NET-1 |
| **CIDR Block** | 38.172.160.0/19 |
| **Country** | Venezuela (VE) |
| **City** | Barquisimeto, Lara |
| **RIR** | ARIN |
Geolocation Validation: Geo-location is plausible (consensus: true), though ICMP validation was unable to complete due to network blocking. Transit analysis indicates 29 hops through Comcast and Cogent networks.
---
THREAT PROFILE
| Indicator | Status |
|---|---|
| **Risk Score** | 25/100 |
| **Abuse Confidence** | Not applicable |
| **Blacklist Count** | 0 |
| **DNSBL Listed** | 1/8 lists |
| **Known Campaigns** | None |
| **Known Attacker** | No |
| **Spam Source** | No |
| **Tor Exit** | No |
| **VPS/Hosting** | No |
Threat Indicators: No active threat feeds, known campaigns, or abuse confidence scores detected. The IP maintains a clean reputation profile with no historical malicious activity.
---
NETWORK CLASSIFICATION
| Attribute | Classification |
|---|---|
| **Infrastructure Type** | Firewalled / No Services |
| **Open Ports** | None |
| **TLS Certificates** | None |
| **DNS Records** | None |
| **Email Auth** | No SPF/DMARC |
| **CDN/Cloud** | No |
| **Mobile/Residential** | No |
| **Bogon** | No |
The IP shows no active services, consistent with a residential or firewalled infrastructure endpoint. No ports were scanned or open during observation.
---
SUBNET NEIGHBORHOOD ANALYSIS
Subnet: 38.172.162.90/24
Abuse Density: 0% (Clean)
Total Siblings: 4
Active Siblings: 0
Neighbor Risk Distribution:
- 38.172.162.55: Risk Score 25 (Low)
- 38.172.162.57: Risk Score 0 (Low)
- 38.172.162.76: Risk Score 0 (Low)
Assessment: The /24 subnet demonstrates a clean profile with no inherited risk. No threat siblings detected in the immediate neighborhood.
---
OBSERVATION HISTORY
Total Observations: 17 signals
Last Observed: 2026-07-31 05:00:53 UTC
Recent Activity Patterns:
- ICMP validation attempts blocked (unable to validate)
- Traceroute completed with 29 hops through US transit (JFK, Cogent)
- Multiple port scans detected but no open services
- No certificate matches or campaign correlations
- Geo-location consistently shows Venezuela with plausible validation
Temporal Analysis: No persistent malicious behavior detected. Threat observation count remains at zero with no ownership changes.
---
RELATIONSHIP GRAPH
Total Relationships: 7
Primary Associations: RED-SERVITEL-CGNT-NET-1 network (7x)
No hostname, certificate, or external organization relationships detected beyond the network infrastructure.
---
RECOMMENDATIONS
Action Status: No immediate action required
Risk Level: Low (25/100)
Firewall Rules: None generated
Analysis Notes:
- IP presents minimal threat to defensive operations
- No recommended blocking or mitigation actions
- Monitor for any changes in threat profile or service activation
- Neighborhood profile supports continued monitoring without escalation
---
CONCLUSION
IP 38.172.162.90 is a low-risk address from a Venezuelan telecommunications provider. The IP is currently inactive with no open services, no known malicious activity, and a clean neighborhood profile. No defensive action is required at this time. Standard monitoring protocols should be maintained.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | RED SERVITEL, CA |
| ASN | AS270026 |
| Network Name | RED-SERVITEL-CGNT-NET-1 |
| CIDR Block | 38.172.160.0/19 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 1 |
| reputation | 0% | 0 | 0 |
| geolocation | 35% | 2 | 2 |
| Overall | 22% | 6 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-30 23:20:40 UTC |
| Last Seen | 2026-08-07 19:25:58 UTC |
| Profile Built | 2026-07-31 05:02:58 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.