## INTELLIGENCE BRIEFING: 38.246.32.70
EXECUTIVE SUMMARY
IP address 38.246.32.70 operates as a low-risk (risk score 30) web server endpoint within the Limestone Networks, Inc. infrastructure. Current threat indicators are absent, with no blacklist presence or known campaign associations. Historical data reveals minor inconsistencies requiring correlation with additional intelligence sources.
---
NETWORK OWNERSHIP & GEOLOCATION
Organization: Limestone Networks, Inc. (AS46475)
Network Block: 38.246.32.0/24
Registration: ARIN RIR
Reported Location: Frankfurt am Main, Hesse, Germany (DE)
PTR Hostname: 70-32-246-38.static.reverse.lstn.net
Domain: lstn.net
*Note: Historical observations have shown conflicting geolocation data (US coordinates observed in some signals). Correlation with current authoritative records recommended.*
---
THREAT ASSESSMENT
Current Risk Score: 30/100 (Low Risk)
Abuse Confidence: Not applicable (no active threats observed)
Blacklist Status: Clean (0 listings)
Known Campaigns: None identified
Tor Exit Node: No
Known Attacker: No
Spam Source: No
---
NETWORK SERVICES EXPOSURE
The following services are actively listening on the endpoint:
| Port | Protocol | Service | Risk Assessment |
|---|---|---|---|
| 443 | TCP | HTTPS | Standard web traffic |
| 22 | TCP | SSH | Administrative access |
| 8080 | TCP | HTTP-ALT | Alternative HTTP port |
| 3389 | TCP | RDP | Remote Desktop Protocol |
*The presence of RDP (3389) and SSH (22) ports warrants monitoring for unauthorized access attempts, though the IP itself shows no malicious activity.*
---
SUBNET ANALYSIS (38.246.32.0/24)
Abuse Density: 0.0
Subnet Classification: Clean
Neighbor Count: 1 active sibling (38.246.32.180, risk score 30)
Threat Siblings: 0
The /24 subnet demonstrates minimal abuse activity with a clean classification rating.
---
HISTORICAL OBSERVATION TREND
Total signals observed: 21
Key historical observations include:
- Recent activity on 2026-07-30 showing connection attempts and service banner analysis
- Historical ASN associations with AS174 (Cogent Communications) observed in some signals
- Geolocation signals have shown inconsistency between Germany and US coordinates
- No evidence of persistent malicious activity over the observation period
---
RELATIONSHIP GRAPH
Associated Entities:
- Network: LIMESTONE-NETWORKS-CGNT-NET-16 (5 relationships)
- DNS Hostname: 70-32-246-38.static.reverse.lstn.net (4 relationships)
No certificate associations or organizational linkages detected beyond network infrastructure.
---
RECOMMENDED ACTIONS
Based on current risk profile (score 30), no immediate blocking or filtering actions are recommended. The IP operates within normal infrastructure parameters with no malicious indicators.
Monitoring Considerations:
1. Monitor RDP (3389) and SSH (22) port access for unauthorized connection attempts
2. Track any changes in geolocation consistency
3. Continue monitoring for emergence of threat indicators
Classification: Routine infrastructure endpoint. No immediate threat.
---
INTELLIGENCE SOURCES
- IPDebrief profile data
- Historical signal observations (21 events)
- Subnet neighborhood analysis
- Control plane routing data
- DNS resolution records
*End of Briefing*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Limestone Networks, Inc. |
| ASN | AS46475 |
| Network Name | LIMESTONE-NETWORKS-CGNT-NET-16 |
| CIDR Block | 38.246.32.0/24 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 70-32-246-38.static.reverse.lstn.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 70-32-246-38.static.reverse.lstn.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| 8080 | http-alt | tcp | โ |
| 3389 | rdp | tcp | โ |
| Closed Ports | 25, 80, 8443 (4 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_7.6p1 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 25% | 1 | 1 |
| services | 35% | 2 | 2 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 14% | 4 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-24 14:26:32 UTC |
| Last Seen | 2026-07-30 00:08:42 UTC |
| Profile Built | 2026-07-30 00:18:54 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 22 |
Full dossier details are available via our API.