## IP Intelligence Briefing: 38.49.54.212/32
Executive Summary
IP address 38.49.54.212 presents a low-risk threat profile with no active malicious indicators. The address is assigned to KURUN CLOUD INC within the Comcast (ASN 8796) infrastructure and is classified as clean with zero abuse density in its /24 subnet. No actionable threats require immediate SOC attention.
---
Technical Profile
Risk Assessment: Low Risk (Score: 25/100)
Ownership: KURUN CLOUD INC | ASN: 8796 | CIDR: 38.49.0.0/18
Network: KURUN-CGNT-NET-3
Geolocation: Los Angeles, California, United States
Classification: Clean / No Services Detected
Service Status: Firewalled / No Open Ports
---
Threat Indicators
- Threat Indicators: None detected
- Blacklist Status: Not listed (0/0 blacklists)
- Known Attacker: False
- Tor Exit Node: False
- Spam Source: False
- Abuse Confidence: Not applicable (no abuse signals)
- Campaign Affiliation: No matches to known campaigns
---
Network Behavior
- DNS Resolution: No PTR records; no reverse DNS resolution
- Email Reputation: No email authentication records (SPF/DMARC)
- HTTP/HTTPS: No web services detected
- Port Scan: No open ports identified
- Network Role: Infrastructure host with no active services
- Anycast: No
---
Neighborhood Analysis
Subnet assessment for 38.49.54.0/24 indicates a clean environment:
- Abuse Density: 0%
- Active Siblings: 0
- Threat Siblings: 0
- Risk Distribution: High: 0, Medium: 0, Low: 0
---
Relationship Graph
The IP address exhibits only network-level relationships:
- Same Network: KURUN-CGNT-NET-3 (3 instances)
- No connections to external organizations, hostnames, or certificates detected
- No certificate subject matches
---
Historical Observations
Analysis of 14 historical observations reveals consistent benign behavior:
- Classification Stability: Maintained "clean" classification throughout observation period
- Ownership: Stable (0 ownership changes recorded)
- Geolocation: Consistent US-based location reporting
- Threat Persistence: 0 days of persistent malicious activity
- Recent Activity: Last observation recorded 2026-07-27 with no threat signals
---
Recommended Actions
Current Risk Level: Low (Score: 25/100)
Recommended Action: Monitor / No Immediate Blocking Required
No specific firewall rules or blocking recommendations are warranted at this time. The IP should be permitted with standard logging and monitoring policies in place.
---
Intelligence Conclusion
38.49.54.212 is a benign IP address assigned to cloud infrastructure provider KURUN CLOUD INC. The subnet demonstrates no abuse indicators, and historical data confirms stable, non-malicious behavior. No immediate threat response actions are required. Continue standard monitoring protocols.
*Report generated: Current data timestamp*
*Classification: Unrestricted*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | KURUN CLOUD INC |
| ASN | AS8796 |
| Network Name | KURUN-CGNT-NET-3 |
| CIDR Block | 38.49.0.0/18 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | — |
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 80, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | *.intel.comintel.com |
| Valid From | 2026-07-07T00:00:00+00:00 |
| Valid Until | 2026-10-05T23:59:59+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256ECDSA |
| Validity Period | 90 days |
🛡️ Public Network Snapshot
| Origin ASN | AS8796 |
| Network Prefix | 38.49.54.0/24 |
| Route mapping | Found |
| HSTS | Not detected |
| CSP | Not detected |
| HTTP/2 | Not detected |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 5 |
| routing | 8% | 1 | 1 |
| services | 31% | 2 | 5 |
| ownership | 23% | 2 | 4 |
| reputation | 25% | 1 | 4 |
| geolocation | 34% | 2 | 5 |
| Overall | 25% | 10 | 24 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-15 16:16:40 UTC |
| Last Seen | 2026-09-03 14:04:02 UTC |
| Profile Built | 2026-09-03 14:28:28 UTC |
| Data Freshness | Live |
| Signal Types | 28 |
| Total Observations | 47 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 38.49.54.212
Who owns the IP address 38.49.54.212?
38.49.54.212 is registered to KURUN CLOUD INC. The address falls within the 38.49.0.0/18 network block. Registration is held at ARIN.
Where is 38.49.54.212 located?
Geolocation data places 38.49.54.212 in Los Angeles, CA, United States. The local time zone is America/Los_Angeles. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 38.49.54.212 malicious or safe?
38.49.54.212 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 38.49.54.212?
Responsive ports observed on 38.49.54.212 include 443, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.