# INTELLIGENCE BRIEFING: 38.3.133.77/32
Classification: LOW RISK
Report Date: Current
Analyst: IPDebrief Intelligence Unit
---
## EXECUTIVE SUMMARY
IP address 38.3.133.77 is assigned to Cogent Communications, LLC (AS274614) within the COGENT-A network. The asset presents a low-risk profile with zero threat indicators, zero blacklist listings, and no observed malicious activity. Geolocation data exhibits moderate inconsistency between current profile (Brazil) and historical observations (US), warranting continued monitoring.
---
## ASSET PROFILE
| Attribute | Value |
|---|---|
| **IP Address** | 38.3.133.77/32 |
| **Risk Score** | 0.00 (Low Risk) |
| **Organization** | Cogent Communications, LLC |
| **ASN** | 274614 |
| **Network** | COGENT-A (38.3.133.0/24) |
| **RIR** | ARIN |
| **Allocated** | 1991-04-16 |
| **Geolocation** | Brazil (BR) β Primary; US (Historical) |
| **Network Role** | Firewalled / No Services |
---
## THREAT INTELLIGENCE
Threat Status: CLEAN
- Blacklist Count: 0
- Known Attacks: None
- Spam Source: No
- Tor Exit Node: No
- Active Campaigns: None
- Threat Feeds: Empty
Network Behavior:
- No open ports detected
- No TLS certificates or HTTP services observed
- DNS forward resolution: Not confirmed
- PTR records: None
- Email authentication: No SPF/DMARC records
---
## OBSERVATION HISTORY
Total Observations: 12
Latest Signal Date: 2026-07-29
Signal Summary:
- Geolocation: Mixed signals (US in historical data, Brazil in current profile; confidence 0.35)
- DNSSEC: Valid (confidence 0.90)
- Blacklist Monitoring: 8 total lists monitored, 0 current listings
- ASN Information: Consistent with AS274614
Temporal Analysis:
- Ownership changes: 0
- Threat persistence days: 0
- Threat observation count: 0
- Persistently malicious: False
---
## NETWORK RELATIONSHIPS
Connected Entities: 1
- COGENT-A (Network) β Same network classification
Cross-Reference: No additional relationships identified (hostnames, organizations, certificates, or related IPs).
---
## SUBNET NEIGHBORHOOD ANALYSIS
Subnet: 38.3.133.77/24
- Neighbor Count: 0
- Abuse Density: 0.00
- Risk Distribution: No high/medium/low risk siblings detected
- Threat Siblings: 0
- Active Siblings: 0
Conclusion: The /24 subnet exhibits benign activity with no correlated malicious neighbors.
---
## TECHNICAL INDICATORS
Control Plane:
- BGP Prefix: 38.3.133.0/24
- Route Changes (30d): 0
- Route Stability: False
- RPKI State: Not reported
- DNSSEC Valid: True
Connectivity:
- Traceroute Hop Count: 16
- First Hop RTT: 0.3ms
- Last Hop RTT: 146.8ms
- Timed Out Hops: 4
- Transit Networks: Comcast
---
## RECOMMENDED ACTIONS
Current Risk Level: LOW
Action Priority: MONITOR
Recommended Measures:
1. No immediate firewall rules required
2. Continue routine geolocation validation due to Brazil/US discrepancy
3. Monitor for service activation (current state: no open ports/services)
4. Maintain blacklist monitoring (currently clean)
Firewall Rules: Not applicable (no risk indicators warranting blocking)
---
## ANALYST NOTES
This IP address represents a legitimate Cogent Communications infrastructure asset with no observed threat activity. The geolocation inconsistency between profile and historical data should be noted but does not currently indicate malicious behavior. The subnet shows clean activity with no threat siblings. Standard monitoring protocols are sufficient; no blocking or alerting actions are recommended at this time.
---
End of Briefing
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Cogent Communications, LLC |
| ASN | AS274614 |
| Network Name | COGENT-A |
| CIDR Block | 38.0.0.0/8 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | 1970-01-01T00:00:00+00:00 |
| Valid Until | 2038-01-19T03:14:07+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 24855 days |
| Serial Number | 00DAC77A29AB3D423C |
| Thumbprint | 776E8673F7AFEF98AB59D4804E9F67D3C3EFF6E8 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 8% | 2 | 3 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-24 02:13:58 UTC |
| Last Seen | 2026-07-29 21:30:24 UTC |
| Profile Built | 2026-07-29 21:40:07 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 20 |
Full dossier details are available via our API.