IPDebrief

38.253.165.84

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 38.253.165.84/32

## Executive Summary

IP address 38.253.165.84 was classified as high risk with a risk score of 70/100 during profile analysis. The IP is registered to WI-NET Telecom SAC under CIDR block 38.253.128.0/18, and network classification indicates residential endpoint infrastructure.

## Ownership and Network Classification

The IP belongs to WI-NET Telecom SAC (ASN: 265691), netname WTSA-CGNT-NET-1, within the ARIN registry. Geolocation data places the IP in the United States with coordinates 39.83, -98.58 (2,500 km accuracy radius). Network role analysis confirmed residential endpoint classification. The IP is not associated with cloud, CDN, VPN, proxy, Tor, hosting, or mobile infrastructure.

## Threat Indicators and Reputation

Threat indicators returned no specific indicators. The IP is not flagged as a Tor exit node, known attacker, or spam source. Blacklist count was zero. However, DNSBL analysis indicated the IP was listed on 4 of 8 total blacklist feeds. Operator score was minimal at 0.1304.

## Service and Port Analysis

No open ports were detected during service enumeration. No TLS certificates, HTTP title, or server banners were observed. No hosted domains were associated with the IP. DNS analysis showed no PTR hostnames and forward resolution was unconfirmed. Email authentication was absent (no SPF or DMARC records).

## Historical Observation Summary

Twelve observations were recorded across the observation period. Recent signals confirmed residential infrastructure classification with 95% confidence. Geolocation data showed US country attribution with 35% confidence. No persistent malicious activity or ownership changes were observed. Threat persistence days and threat observation count were zero.

## Neighborhood Analysis

The /24 subnet (38.253.165.84/24) contained no neighboring IP data. Abuse density was zero with no sibling IPs detected. Risk distribution across the subnet showed no high, medium, or low risk classifications.

## Network Control Plane

Control plane analysis identified origin ASN 265691 with BGP prefix 38.253.128.0/18. Route stability was false. The IP traversed 13 hops via traceroute, with transit networks including Comcast. Two hops timed out during probing.

## Recommended Security Actions

Based on risk score 70/100, the following actions were recommended:

Monitoring:

Firewall Rules:

## SOC Analyst Notes

This IP requires monitoring due to elevated risk score and DNSBL listings. The residential classification combined with multiple blacklist detections suggests potential for malicious use. No active attack signatures were observed, but the IP should be blocked at perimeter defenses per recommended actions.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionOH
CityLima
Timezoneβ€”
Latitude40.74
Longitude-84.11

🏒 Ownership & Registration

OrganizationWI-NET Telecom SAC
ASNAS265691
Network NameWTSA-CGNT-NET-1
CIDR Block38.253.128.0/18
RIRARIN
CountryUnited States
Abuse Contactβ€”

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)

πŸ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureResidential
Service PurposeResidential Endpoint
Network TierEnd-User β€” Residential ISP endpoint
Residential

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
0%
00
reputation
0%
00
geolocation
0%
00
Overall12%33
Coverage: 3/6 dimensions Β· Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-07-24 08:18:46 UTC
Last Seen2026-08-02 17:02:34 UTC
Profile Built2026-07-29 22:54:49 UTC
Data FreshnessLive
Signal Types13
Total Observations13
πŸ” 13 signal types Β· 13 observations collected
This report is generated from 13+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.