# IP INTELLIGENCE BRIEFING: 139.28.190.241/32
Classification: Moderate Risk | Risk Score: 55/100 | Date: 2026-06-26
## Executive Summary
IP 139.28.190.241 is a moderate-risk web server located in Malagon, Spain, operating on ASN 200845 (Mnt-Wikiker). The IP presents low direct threat indicators but resides within a subnet with elevated abuse activity (0.3051 abuse density). No active campaigns or known attacker associations detected.
## Technical Profile
Geolocation:
- Country: ES (Spain)
- Region: CM (Comunidad de Madrid)
- City: Malagon
- Coordinates: Not available
- Geoconsensus: Validated across 2 sources
Network Infrastructure:
- ASN: 200845
- Organization: Mnt-Wikiker
- BGP Prefix: 139.28.188.0/22
- Route Stability: Unstable
- DNSBL Listings: 3 of 8 lists (listed)
Service Profile:
- Role: Web Server
- Open Ports: TCP/80 (HTTP), TCP/443 (HTTPS)
- Server Banner: lighttpd/1.4.39
- TLS Certificates: None detected
- Email Authentication: SPF/DMARC not configured
Reputation Indicators:
- Not a Tor exit node
- Not flagged as known attacker or spam source
- Blacklist count: 0
- Abuse confidence score: Not assigned
## Neighborhood Analysis
Subnet Context: 139.28.190.0/24
- Total sibling IPs: 59
- Active siblings: 11
- Threat siblings: 18
- Abuse density: 0.3051 (elevated)
- Subnet classification: Mixed
- Inherited risk: 12
Risk Distribution:
- High risk: 5 IPs (e.g., 139.28.190.0: 80)
- Medium risk: 52 IPs
- Low risk: 11 IPs
Notable Neighbors:
- 139.28.190.0: Risk 80 (high)
- 139.28.190.4: Risk 55 (moderate)
- 139.28.190.12: Risk 0 (clean)
- 139.28.190.124: Risk 40 (low)
## Historical Observations
Timeline: 17 observations recorded
- Most recent signal: 2026-06-26 (minimal risk, operator score 0)
- Previous signals: Connection failures (2026-06-18), subnet analysis (2026-06-05)
- Threat persistence: 0 days
- Campaign likelihood: None
Signal Evolution: No significant risk trajectory identified. IP has remained in the moderate risk category with no escalation patterns.
## Relationship Graph
Connected Entities: 15 relationships identified
- All relationships classified as "Same Network"
- Network identifier: ES-AVATELTELECOM-20190103
- No cross-organization or external network associations detected
## Recommended Actions
Detection & Blocking:
- Monitor for outbound connections to high-risk neighbors in 139.28.190.0/24
- Implement DNSBL monitoring (currently listed on 3 of 8 lists)
- Flag for review if risk score exceeds threshold of 70
MITRE ATT&CK Relevance:
- No direct correlation to known TTPs
- Neighborhood context suggests potential lateral movement risk from associated high-risk IPs
Firewall Rules Consideration:
- Allow outbound HTTP/HTTPS if legitimate business use confirmed
- Block inbound unsolicited connections
- Monitor for beaconing behavior to neighbors 139.28.190.0 and 139.28.190.4
---
Analyst Notes: The IP presents minimal direct threat but warrants monitoring due to subnet-level abuse activity. The lighttpd/1.4.39 banner is outdated (no security updates since 2014), which could indicate poor maintenance. No immediate threat mitigation required, but maintain awareness of neighborhood threat landscape.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Mnt-Wikiker |
| ASN | AS200845 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | lighttpd/1.4.39 |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 24% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 19% | 2 | 2 |
| Overall | 20% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-10 16:13:56 UTC |
| Last Seen | 2026-06-26 02:07:20 UTC |
| Profile Built | 2026-06-26 02:13:07 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 19 |
Full dossier details are available via our API.