# IP Intelligence Briefing: 38.253.165.84/32
## Executive Summary
IP address 38.253.165.84 was classified as high risk with a risk score of 70/100 during profile analysis. The IP is registered to WI-NET Telecom SAC under CIDR block 38.253.128.0/18, and network classification indicates residential endpoint infrastructure.
## Ownership and Network Classification
The IP belongs to WI-NET Telecom SAC (ASN: 265691), netname WTSA-CGNT-NET-1, within the ARIN registry. Geolocation data places the IP in the United States with coordinates 39.83, -98.58 (2,500 km accuracy radius). Network role analysis confirmed residential endpoint classification. The IP is not associated with cloud, CDN, VPN, proxy, Tor, hosting, or mobile infrastructure.
## Threat Indicators and Reputation
Threat indicators returned no specific indicators. The IP is not flagged as a Tor exit node, known attacker, or spam source. Blacklist count was zero. However, DNSBL analysis indicated the IP was listed on 4 of 8 total blacklist feeds. Operator score was minimal at 0.1304.
## Service and Port Analysis
No open ports were detected during service enumeration. No TLS certificates, HTTP title, or server banners were observed. No hosted domains were associated with the IP. DNS analysis showed no PTR hostnames and forward resolution was unconfirmed. Email authentication was absent (no SPF or DMARC records).
## Historical Observation Summary
Twelve observations were recorded across the observation period. Recent signals confirmed residential infrastructure classification with 95% confidence. Geolocation data showed US country attribution with 35% confidence. No persistent malicious activity or ownership changes were observed. Threat persistence days and threat observation count were zero.
## Neighborhood Analysis
The /24 subnet (38.253.165.84/24) contained no neighboring IP data. Abuse density was zero with no sibling IPs detected. Risk distribution across the subnet showed no high, medium, or low risk classifications.
## Network Control Plane
Control plane analysis identified origin ASN 265691 with BGP prefix 38.253.128.0/18. Route stability was false. The IP traversed 13 hops via traceroute, with transit networks including Comcast. Two hops timed out during probing.
## Recommended Security Actions
Based on risk score 70/100, the following actions were recommended:
Monitoring:
- Increase logging verbosity and review recent activity from this IP
Firewall Rules:
- iptables: `iptables -A INPUT -s 38.253.165.84 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 38.253.165.84 drop`
- nginx: `deny 38.253.165.84;`
- pfSense: `38.253.165.84/32`
- Cloudflare WAF: Block with expression `ip.src eq 38.253.165.84`
- AWS WAF: Add address `38.253.165.84/32` with description "IPDebrief risk 70"
## SOC Analyst Notes
This IP requires monitoring due to elevated risk score and DNSBL listings. The residential classification combined with multiple blacklist detections suggests potential for malicious use. No active attack signatures were observed, but the IP should be blocked at perimeter defenses per recommended actions.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | WI-NET Telecom SAC |
| ASN | AS265691 |
| Network Name | WTSA-CGNT-NET-1 |
| CIDR Block | 38.253.128.0/18 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | β |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Residential |
| Service Purpose | Residential Endpoint |
| Network Tier | End-User β Residential ISP endpoint |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-24 08:18:46 UTC |
| Last Seen | 2026-08-02 17:02:34 UTC |
| Profile Built | 2026-07-29 22:54:49 UTC |
| Data Freshness | Live |
| Signal Types | 13 |
| Total Observations | 13 |
Full dossier details are available via our API.