THREAT INTELLIGENCE BRIEFING
Target: 38.242.232.161/32
Classification: Low Risk / Cloud Hosting Infrastructure
Report Date: Current
---
EXECUTIVE SUMMARY
IP 38.242.232.161 is a low-risk address (risk score: 15) associated with cloud compute infrastructure provided by Contabo. The IP is hosted within Cogent Communications' COGENT-A network block (38.0.0.0/8), geolocated to Newark, New Jersey, USA. The subnet classification is "clean" with zero abuse density and no high-risk neighbors. No active threat indicators, malware campaigns, or malicious behavior patterns detected.
---
TECHNICAL PROFILE
Ownership & Network:
- ASN: 51167 (Cogent Communications, LLC)
- Network Name: COGENT-A
- CIDR Block: 38.0.0.0/8
- Provider Classification: Contabo (Cloud Compute)
- Infrastructure Type: Cloud Hosting
- ISP Classification: Cloud (Yes), Hosting (Yes)
- Registration: ARIN
Geolocation:
- Country: United States (US)
- Region: New Jersey (US-NJ)
- City: Newark
- Timezone: America/New_York
- Accuracy: 2,500 km radius
DNS & Resolution:
- PTR Hostname: sma360.mywebvas.com
- Reverse DNS: Confirmed
- Forward Resolution Count: 1
- Email Authentication: SPF and DMARC records present
Network Services:
- Open Ports: None detected
- TLS Certificate: Not detected
- HTTP Title: Not detected
- Service Purpose: Firewalled / No Services
---
THREAT INTELLIGENCE
Current Risk Assessment:
- Overall Risk Score: 15 (Low)
- Abuse Confidence Score: Not applicable
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Blacklist Count: 0 (1 out of 8 DNSBL lists checked, maximum severity: medium)
Threat Indicators:
- Active Campaigns: None detected
- Known Malware/Threat Feeds: Empty
- Honeypot Hits: 0
- Persistently Malicious: No
Control Plane:
- Origin ASN: 51167
- BGP Prefix: 38.242.224.0/19
- Route Stability: False
- DNSSEC Valid: Yes
- DNSBL Listed Count: 1 of 8 total lists
---
OBSERVATION HISTORY
Historical Signals: 17 observations recorded
Recent Activity: 2026-07-29
Threat Persistence: 0 days
Threat Observation Count: 0
Ownership Changes: 0
Is Persistently Malicious: False
Signal Summary:
- Network role classification: Cloud hosting with Contabo infrastructure
- Geolocation data: US-based with moderate confidence (0.35)
- DNS records: Associated with mywebvas.com domain
- No escalation in threat posture over observation period
---
RELATIONSHIP ANALYSIS
Connected Entities:
1. DNS Association: sma360.mywebvas.com (hostname)
2. Network Association: COGENT-A (network)
Network Neighborhood (38.242.232.0/24):
- Subnet Classification: Clean
- Abuse Density: 0
- Total Siblings: 3
- Active Siblings: 2
- Threat Siblings: 0
Neighbor Risk Profiles:
- 38.242.232.20: Risk Score 0, Authority Score 60 (Low Risk)
- 38.242.232.186: Risk Score 25, Authority Score 50 (Low Risk)
---
RECOMMENDED ACTIONS
Security Recommendations: No specific firewall rules or blocking actions required at this time.
Rationale: The IP demonstrates low-risk characteristics consistent with legitimate cloud hosting infrastructure. No active threat indicators, no malicious behavior detected, and the surrounding subnet is classified as clean.
SOC Analyst Guidance: Monitor for changes in threat posture. If this IP begins exhibiting suspicious behavior (port scans, brute force attempts, spam generation), implement appropriate blocking rules. The absence of open services suggests the address may be reserved or in a non-operational state.
---
END OF BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Cogent Communications, LLC |
| ASN | AS51167 |
| Network Name | COGENT-A |
| CIDR Block | 38.0.0.0/8 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | sma360.mywebvas.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | sma360.mywebvas.com |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | Caddy |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_10.2p1 Ubuntu-2ubuntu3.5 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 17% | 1 | 1 |
| Overall | 21% | 9 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-23 01:41:35 UTC |
| Last Seen | 2026-08-12 17:25:31 UTC |
| Profile Built | 2026-08-12 17:41:00 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 22 |
Full dossier details are available via our API.