# IP Intelligence Briefing: 38.253.166.46/32
Classification: Moderate Risk (Score: 50)
Date: 2026-07-30
Status: Active Observation
---
## Executive Summary
IP address 38.253.166.46 is classified as a residential web server with moderate risk exposure. The IP belongs to WI-NET Telecom SAC (ASN 265691) within the WTSA-CGNT-NET-1 network block (38.253.128.0/18). Key concerns include geolocation inconsistencies, open RDP port exposure, and presence in 2 of 8 DNSBL listings. No active threat campaigns or known attacker attribution currently associated.
---
## Network & Ownership Intelligence
- ASN: 265691 (WI-NET Telecom SAC)
- Organization: WI-NET Telecom SAC
- Network Block: 38.253.128.0/18
- Classification: Residential Infrastructure
- Service Purpose: Web Server
- RIR: ARIN
---
## Threat Indicators
| Indicator | Status |
|---|---|
| Known Attacker | No |
| Tor Exit Node | No |
| Spam Source | No |
| Active Campaigns | None |
| Blacklist Count | 2 of 8 DNSBL lists |
| Abuse Confidence Score | Not reported |
---
## Technical Profile
Open Services
- Port 80/tcp: HTTP
- Port 443/tcp: HTTPS
- Port 3389/tcp: RDP (Remote Desktop Protocol) β οΈ
DNS Analysis
- PTR Hostnames: None
- Forward Resolution: Not confirmed
- Hosted Domains: 0
- Email Authentication: None (No SPF/DMARC records)
- DNSSEC: Valid
Network Classification
- Residential: Yes
- Cloud/CDN/Vpn/Proxy: No
- Anycast: No
- Hosting Provider: No
---
## Geolocation Analysis
Status: GEOLOCATION INCONSISTENT β οΈ
- Claimed Country: United States
- Distance from Claimed Location: 10,587 km
- Observed RTT: 106.6ms average
- Minimum Possible RTT: 211.7ms for claimed distance
- GeoPlausible: False
*Analysis: Significant RTT and distance violations indicate geolocation data may be spoofed or unreliable. This inconsistency warrants monitoring.*
---
## Observation History (13 Signals)
Recent signals (2026-07-30):
- Connection failures detected on HTTPS probes
- Residential classification consistent across observations
- ASN and network registration stable
- No threat persistence indicators
---
## Neighborhood Analysis
- /24 Subnet: 38.253.166.0/24
- Neighboring IPs: 0 active
- Abuse Density: 0
- Threat Siblings: 0
*The /24 neighborhood shows no adjacent malicious activity.*
---
## Recommended Actions
Firewall Rules (Probabilistic - validate with additional signals):
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 38.253.166.46 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 38.253.166.46 drop` |
| nginx | `deny 38.253.166.46;` |
| pfSense | `38.253.166.46/32` |
| Cloudflare WAF | Block IP with filter expression `ip.src eq 38.253.166.46` |
| AWS WAF | Add IP 38.253.166.46/32 to deny list |
---
## SOC Analyst Recommendations
1. Monitor RDP Exposure: Port 3389 is open. Verify if this is intentional for remote administration or misconfiguration.
2. Geolocation Validation: The RTT/distance violation suggests potential spoofing. Correlate with other indicators.
3. DNSBL Review: Investigate which 2 of 8 DNSBL lists the IP is listed on to understand abuse context.
4. Traffic Pattern Analysis: Monitor for RDP connection attempts from this IP to your infrastructure.
5. No Immediate Block Required: Risk score of 50 is moderate; implement block rules if additional threat signals emerge.
---
End of Briefing
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | WI-NET Telecom SAC |
| ASN | AS265691 |
| Network Name | WTSA-CGNT-NET-1 |
| CIDR Block | 38.253.128.0/18 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | β |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Residential |
| Service Purpose | Web Server |
| Network Tier | End-User β Residential ISP endpoint |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 3389 | rdp | tcp | β |
| Closed Ports | 22, 25, 8080, 8443 (3 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 35% | 2 | 2 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 14% | 4 | 4 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-27 21:54:33 UTC |
| Last Seen | 2026-08-01 16:33:41 UTC |
| Profile Built | 2026-07-30 14:47:27 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.