# IPDEBRIEF INTELLIGENCE BRIEFING
Target: 38.60.214.183/32
Classification: Low Risk / Clean
Report Date: Current
---
## EXECUTIVE SUMMARY
IP address 38.60.214.183 is a low-risk infrastructure address with no active malicious indicators. The IP belongs to LightNode-TW network (ASN 154177) and shows no evidence of abuse, command-and-control activity, or threat actor association. No security actions are currently recommended for defensive filtering.
---
## RISK PROFILE
| Metric | Value |
|---|---|
| **Risk Score** | 25 (Low Risk) |
| **Provider Score** | 0 |
| **Authority Score** | 0 |
| **Stability Score** | 0 |
| **Abuse Confidence** | Not reported |
| **Blacklist Count** | 0 |
| **Known Campaigns** | None detected |
---
## OWNERSHIP & GEOLOCATION
| Field | Value |
|---|---|
| **ASN** | 154177 |
| **Organization** | LightNode-TW |
| **Network Block** | 38.60.214.0/24 |
| **Country** | US |
| **RIR** | ARIN |
| **Registration** | No registration date available |
Note: Geographic data shows some inconsistency across sources. Primary consensus indicates US location, though alternative sources report Taiwan/Hong Kong. Geo validation flagged ICMP blocking preventing full validation (9,416.5 km distance reported).
---
## NETWORK & SERVICE ANALYSIS
| Attribute | Status |
|---|---|
| **Open Ports** | None detected |
| **Services** | Firewalled / No Services |
| **CDN/Proxy/VPN** | No |
| **Cloud/Hosting** | No |
| **Tor Exit Node** | No |
| **Residential IP** | No |
| **HTTP Title** | None |
| **TLS Certificate** | None |
---
## THREAT INDICATORS
- Threat Feeds: Empty
- Indicators: None
- Reputation Sources: None
- DNSBL Lists: 1 out of 8 total lists
- Known Attacker: False
- Spam Source: False
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: 0
- Total Incidents: 0
---
## NEIGHBORHOOD ANALYSIS
Subnet: 38.60.214.0/24
Abuse Density: 0
Classification: Clean
Total Siblings: 1
Active Siblings: 0
Threat Siblings: 0
Risk Distribution:
- High Risk: 0
- Medium Risk: 0
- Low Risk: 0
No neighboring IPs in the /24 subnet show malicious activity. The subnet demonstrates clean classification with no inherited risk.
---
## CONTROL PLANE DATA
| Metric | Value |
|---|---|
| **Origin ASN** | 154177 |
| **BGP Prefix** | 38.60.214.0/24 |
| **Route Changes (30d)** | 0 |
| **Route Stable** | False |
| **RPKI State** | Not reported |
| **IRR Consistency** | Not reported |
| **DNSSEC Valid** | True |
| **CNAME/CAA Records** | No |
| **Operator Score** | 0.1304 (Minimal) |
---
## OBSERVATION HISTORY
Total Observations: 16
Latest Activity: 2026-07-29
Key historical signals indicate:
- Consistent classification as non-CDN, non-Tor, non-VPN, non-proxy infrastructure
- No persistent malicious behavior detected
- Ownership changes tracked: 0
- Threat persistence days: 0
- Threat observation count: 0
- Neighborhood classification remained "clean" across all observations
---
## RELATIONSHIP GRAPH
Total Relationships: 3
All relationships indicate "Same Network" associations with target value "LIGHTNODE-TW", confirming the IP's network affiliation.
---
## RECOMMENDED ACTIONS
Risk Score: 25
Recommendations: None
Firewall Rules: Not applicable
Given the low risk profile and absence of threat indicators, no immediate defensive actions are recommended. The IP should continue to be monitored as part of normal traffic analysis.
---
## ANALYST NOTES
1. No Immediate Threat: This IP shows no evidence of malicious activity, command-and-control, or abuse patterns.
2. Infrastructure Role: The IP appears to be a firewalled infrastructure node with no exposed services.
3. Network Context: The LightNode-TW network (ASN 154177) shows clean neighborhood metrics with no sibling abuse.
4. Minor Flag: One DNSBL listing detected across 8 total lists—likely a minor false positive or low-priority listing.
5. Monitoring Suggestion: Continue standard monitoring but no elevated threat response warranted at this time.
---
END OF BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | LightNode-TW |
| ASN | AS154177 |
| Network Name | LIGHTNODE-TW |
| CIDR Block | 38.60.214.0/24 |
| RIR | ARIN |
| Country | Hong Kong |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS154177 |
| Network Prefix | 38.60.214.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-20 06:30:43 UTC |
| Last Seen | 2026-09-02 11:15:34 UTC |
| Profile Built | 2026-09-02 11:24:55 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 25 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 38.60.214.183
Who owns the IP address 38.60.214.183?
38.60.214.183 is registered to LightNode-TW. The address falls within the 38.60.214.0/24 network block. Registration is held at ARIN.
Where is 38.60.214.183 located?
Geolocation data places 38.60.214.183 in United States. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 38.60.214.183 malicious or safe?
38.60.214.183 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.