# IP Intelligence Briefing: 43.249.38.194/32
## Executive Summary
The IP address 43.249.38.194 presents a low-risk threat profile with no active malicious indicators. The address is classified as "Low Risk" with a risk score of 0, no blacklist listings, and no known threat campaign associations.
## Current Risk Assessment
- Reputation: Low Risk
- Risk Score: 0
- Provider Score: 0
- Authority Score: 0
- Blacklist Status: Not listed (8 potential lists checked, 0 active)
- Known Campaigns: None detected
## Geolocation Intelligence
Multiple geolocation sources indicate conflicting data:
- Primary classification: US (New York, US-NY)
- Alternative classification: Singapore (SG) from MaxMind GeoLite2
- Network infrastructure: Leaseweb Asia Pacific pte ltd administrator (APNIC RIR)
- CIDR Block: 43.249.38.0/24
The geolocation inconsistency suggests potential multi-region hosting or data source variance. No definitive origin can be established from current data.
## Network Characteristics
- Network Role: Firewall / No Services
- Open Ports: None detected
- DNS: No forward resolution, no PTR records
- Email Auth: No SPF or DMARC records
- TLS Certificates: None observed
- Traceroute: 18 hops, 4 timed out, transit networks include Comcast
- Route Stability: Not route stable (isRouteStable: false)
## Threat Indicators
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Active Attacks: No
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: 0
## Neighborhood Analysis (43.249.38.0/24)
- Total Siblings: 1 neighbor identified
- Abuse Density: 0
- Neighbor Profile: 43.249.38.40 (Risk Score: 0, Authority Score: 50)
- Threat Siblings: 0
The /24 subnet demonstrates minimal abuse activity with only one additional neighbor IP, which also maintains a low-risk profile.
## Historical Observations
Thirteen signal observations recorded, with recent activity including:
- Geolocation updates showing Singapore attribution
- Organization registration under Leaseweb Asia Pacific
- Traceroute attempts with incomplete path resolution
- Blacklist monitoring (8 lists monitored, 0 active listings)
No persistent malicious behavior detected across the observation timeline.
## Recommendations
Based on the risk profile, the following actions are recommended for SOC operations:
1. Monitoring: No immediate blocking required. Standard traffic monitoring recommended.
2. Firewall Rules: No specific deny rules recommended.
3. WAF Rules: No blocking rules required.
4. Threat Hunting: No active threat indicators warrant investigation.
## Conclusion
IP 43.249.38.194 demonstrates a benign threat profile with no active malicious indicators, no known campaign associations, and a clean neighborhood context. The geolocation data inconsistency warrants awareness but does not indicate malicious intent. No defensive actions are currently required beyond standard network monitoring practices.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Leaseweb Asia Pacific pte ltd administrator |
| ASN | AS59253 |
| Network Name | LSW-AS-AP |
| CIDR Block | 43.249.38.0/24 |
| RIR | APNIC |
| Country | SG |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS59253 |
| Network Prefix | 43.249.38.0/24 |
| Route mapping | Found |
| Certificates in transparency logs | 0 certificates |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 41% | 2 | 5 |
| routing | 8% | 1 | 1 |
| services | 20% | 2 | 2 |
| ownership | 23% | 2 | 4 |
| reputation | 27% | 1 | 4 |
| geolocation | 20% | 2 | 2 |
| Overall | 23% | 10 | 18 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-15 10:09:14 UTC |
| Last Seen | 2026-09-05 21:55:25 UTC |
| Profile Built | 2026-09-05 21:56:28 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 28 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 43.249.38.194
Who owns the IP address 43.249.38.194?
43.249.38.194 is registered to Leaseweb Asia Pacific pte ltd administrator. The address falls within the 43.249.38.0/24 network block. Registration is held at APNIC.
Where is 43.249.38.194 located?
Geolocation data places 43.249.38.194 in New York, US-NY, United States. The local time zone is America/New_York. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 43.249.38.194 malicious or safe?
43.249.38.194 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.