# IP Intelligence Briefing: 38.67.211.49/32
Date: 2026-07-30
Classification: Low Risk / Provider Infrastructure
Source: IPDebrief Intelligence Platform
---
## Executive Summary
IP address 38.67.211.49 is classified as Low Risk with an overall risk score of 25. The address belongs to Cogent Communications, LLC (ASN 150150) and operates within the COGENT-A network block (38.0.0.0/8). No active threat indicators, known campaigns, or malicious classifications were detected.
---
## Network Ownership & Classification
- Organization: Cogent Communications, LLC
- ASN: 150150
- Network Name: COGENT-A
- CIDR Block: 38.0.0.0/8
- RIR: ARIN
- Abuse Contact: abuse@cogentco.com (via RDAP)
The IP is classified as provider infrastructure with no CDN, hosting, proxy, or VPN functionality. Network scans indicate the address is firewalled with no active services detected.
---
## Geolocation Assessment
Geolocation data presents conflicting signals requiring validation:
- Primary Report: Hong Kong (HK) โ Wong Tai Sin District, San Po Kong
- Secondary Signal: United States (DC) โ 0.30 confidence level
- Geographic Consensus: Inconsistent across sources
- Geo Validation: Flagged as implausible with 2500km accuracy radius
The conflicting geolocation reports suggest potential routing anomalies or multi-homed infrastructure. Recommend correlating with upstream BGP data for definitive placement.
---
## Threat Intelligence Indicators
- Risk Score: 25 (Low Risk)
- Blacklist Status: 0/8 threat feeds listed
- DNSBL Listings: 1 of 8 total lists (minimal impact)
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Active Campaigns: None detected
- Threat Persistence: 0 days observed
No malicious activity or attack patterns identified within the threat intelligence feeds.
---
## Network Behavior & Services
- Open Ports: None detected
- HTTP/HTTPS Services: None
- TLS Certificates: None
- PTR Hostnames: None resolved
- DNS Records: No forward resolution or hosted domains
- Email Authentication: SPF/DMARC not configured
The IP demonstrates no active service exposure and no email authentication infrastructure.
---
## Control Plane Analysis
- Route Stability: False (0 route changes in 30 days)
- RPKI State: Unknown
- IRR Consistency: Unknown
- BGP Prefix: 38.67.211.0/24
- DNSSEC Validation: Valid
- DNSBL Listed Count: 1 (minimal listing presence)
---
## Observation History
Twelve signal observations recorded between 2026-07-30. Key observations include:
- Ownership change count: 0
- Average ownership days: N/A
- Threat observation count: 0
- Persistently malicious: False
Recent signals indicate stable ownership with no persistent malicious behavior.
---
## Neighborhood Analysis
- Subnet: 38.67.211.0/24
- Neighbor Count: 0
- Abuse Density: 0%
- Risk Distribution: High: 0, Medium: 0, Low: 0
- Threat Siblings: None detected
The /24 subnet shows no neighboring IPs with abuse indicators, suggesting isolated infrastructure.
---
## Intelligence Relationships
Only one relationship detected:
- Same Network: COGENT-A network
No associated hostnames, organizations, certificates, or correlated IPs identified.
---
## Recommended Actions
1. Monitor for geolocation consistency across BGP and DNS sources
2. Allow through standard firewall rules โ no blocking required
3. No immediate action needed โ low risk classification
4. Correlate with upstream provider routing tables for definitive geolocation
5. Track DNSBL listing status for potential reputation changes
---
## Conclusion
IP 38.67.211.49 represents benign provider infrastructure from Cogent Communications with no active threat indicators. The primary intelligence concern is geolocation inconsistency, which warrants monitoring rather than immediate action. No firewall blocking or security interventions are recommended at this time.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Cogent Communications, LLC |
| ASN | AS150150 |
| Network Name | COGENT-A |
| CIDR Block | 38.0.0.0/8 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-27 15:46:49 UTC |
| Last Seen | 2026-07-30 23:20:40 UTC |
| Profile Built | 2026-07-30 13:35:47 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 16 |
Full dossier details are available via our API.