# IP Intelligence Briefing: 38.183.115.124
## Executive Summary
IP address 38.183.115.124 presents moderate risk (score: 50/100) with geolocation inconsistencies and DNSBL listings. The subnet environment appears clean with no active threats observed. No malicious behavior, campaigns, or attack patterns detected.
## Profile Overview
| Attribute | Value |
|---|---|
| **Risk Score** | 50 (Moderate) |
| **Country** | Venezuela (VE) / Inconsistent US signals |
| **ASN** | 269749 |
| **Geolocation** | Valencia, Carabobo |
| **Network Role** | Firewalled / No Services |
| **DNS** | host124.online-plus.com |
| **DNSBL Listed** | 2 of 8 lists |
| **Operator Score** | 0.1304 (Minimal) |
## Threat Assessment
- Threat Indicators: None identified
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Campaigns: No matches
- Honeypot Hits: 0
- WAF Violations: 0
## Behavioral Analysis
- Services: No open ports detected
- Threat Persistence: 0 days observed
- Ownership Changes: 0
- Total Incidents: 0
- Classification: Clean subnet environment
## Neighborhood Context (38.183.115.0/24)
- Abuse Density: 0 (Clean)
- Subnet Classification: Clean
- Active Siblings: 3 of 5
- Neighbor Risk Scores: 25 (low-medium)
- Threat Siblings: 0
- Neighbor IPs:
- 38.183.115.89 (Risk: 25)
- 38.183.115.110 (Risk: 25)
- 38.183.115.113 (Risk: 25)
- 38.183.115.123 (Risk: 25)
## Historical Signals (13 Observations)
Recent observations show geolocation conflicts (Venezuela vs US), ASN references to AS174 Cogent Communications, and low-confidence control plane assessments. Signals indicate minimal operator risk with DNSSEC validation present.
## Recommended Actions
Due to moderate risk score and DNSBL listings, consider blocking:
```bash
# iptables
iptables -A INPUT -s 38.183.115.124 -j DROP
# nftables
nft add rule inet filter input ip saddr 38.183.115.124 drop
# Cloudflare WAF
{"description":"Block 38.183.115.124 โ IPDebrief risk score 50","action":"block","filter":{"expression":"ip.src eq 38.183.115.124"}}
# AWS WAF
{"Addresses":["38.183.115.124/32"],"Description":"IPDebrief risk 50"}
```
## Intelligence Notes
- DNSBL listings (2/8) contribute to risk elevation
- Geolocation inconsistencies suggest potential proxy or residential IP usage
- No active threat indicators or attack patterns observed
- Subnet shows low abuse density with consistent low-risk neighbors
- Minimal operator risk score suggests legitimate but unverified infrastructure
Recommendation: Implement blocking at network perimeter with monitoring. Evaluate against additional threat indicators before permanent blocking action.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | NETCOM PLUS, C.A |
| ASN | AS269749 |
| Network Name | NETCOM-PLUS-CGNT-NET-2 |
| CIDR Block | 38.183.112.0/21 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | host124.online-plus.com |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | host124.online-plus.com |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 25% | 1 | 1 |
| Overall | 22% | 6 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-29 16:42:07 UTC |
| Last Seen | 2026-07-31 13:32:24 UTC |
| Profile Built | 2026-07-30 23:12:04 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 20 |
Full dossier details are available via our API.