# IP Intelligence Briefing: 148.227.122.245/32
Classification: Moderate Risk | Date: Current Analysis
---
## Executive Summary
IP 148.227.122.245 is a residential endpoint associated with Starlink Brazil Serviços de Internet Ltd (ASN 14593), located in Brasília, Brazil. The IP carries a moderate risk score of 55/100 with no active threat indicators detected. The endpoint is currently firewalled with no open services. Neighborhood analysis indicates a 17.65% abuse density within the /24 subnet.
---
## Ownership & Infrastructure
| Attribute | Value |
|---|---|
| **ASN** | 14593 |
| **Organization** | Starlink Brazil Serviços de Internet Ltd |
| **Network** | 148.227.122.0 - 148.227.122.255 |
| **CIDR Block** | 148.227.122.0/24 |
| **RIR** | ARIN |
| **Registration** | Not available |
---
## Geolocation Signals
Multiple geolocation signals were observed:
- Primary: Brasília, Federal District, Brazil (BR)
- Alternative: One signal indicated Mexico (AS22884 total play telecomunicaciones SA de CV, coordinates 19.0439, -98.1984)
- Confidence: Varies by source (0.28โ0.75)
- Geo Consensus: True (Brazil)
Note: Conflicting geolocation signals suggest potential routing anomalies or multi-tenant infrastructure.
---
## Network Role & Services
- Connection Type: Firewalled / No Services
- Open Ports: None detected
- TLS Certificate: Not present
- HTTP Services: None
- Classification: Not cloud, CDN, VPN, proxy, Tor, or hosting provider
- Mobile Carrier: None detected
---
## DNS & Email Reputation
- PTR Record: customer.brsabra1.isp.starlink.com
- Forward Resolution: customer.brsabra1.isp.starlink.com (1 record)
- Email Authentication: SPF: Yes, DMARC: Yes
- TXT Records: 0
- DNSBL Status: Listed on 3 of 8 total lists
- Domain: starlink.com
---
## Threat Indicators
| Indicator | Status |
|---|---|
| **Is Tor Exit Node** | No |
| **Is Known Attacker** | No |
| **Is Spam Source** | No |
| **Blacklist Count** | 0 |
| **Abuse Confidence Score** | Not calculated |
| **Known Campaigns** | None |
| **Threat Feeds** | None |
Control Plane Data:
- DNSSEC Valid: Yes
- CAA Records: Yes
- Route Stability: False
- Route Changes (30d): 0
- Operator Score: 0.2174 (Minimal)
---
## Neighborhood Analysis (148.227.122.0/24)
- Total Siblings: 17
- Active Siblings: 9
- Threat Siblings: 3
- Abuse Density: 0.1765 (17.65%)
- Classification: mostly_clean
- Inherited Risk: 7/100
Neighbor Risk Distribution:
- High Risk (40+): 0 IPs
- Medium Risk (15-39): 6 IPs
- Low Risk (<15): 9 IPs
---
## Observation History (17 Signals)
Recent observations include:
- 2026-07-29 12:28:29: Brazil geolocation (confidence 0.28)
- 2026-07-29 12:27:54: Network classification signals (confidence 0.30)
- 2026-07-29 12:27:15: Mexico ASN 22884 with threat indicators (confidence 0.75)
- 2026-07-29 12:26:44: Neighborhood abuse density 0.1765 (confidence 0.75)
- 2026-07-29 12:26:04: Brasília geolocation via MaxMind (confidence 0.70)
Temporal Data:
- Ownership Changes: 0
- Threat Persistence Days: 0
- Threat Observation Count: 0
- Persistently Malicious: No
---
## Recommended Security Actions
Priority: High
Monitoring Recommendations
- Increase logging verbosity for traffic from this IP
- Review recent activity patterns and connection attempts
Firewall Rules
| Platform | Rule |
|---|---|
| **iptables** | `iptables -A INPUT -s 148.227.122.245 -j DROP` |
| **nftables** | `nft add rule inet filter input ip saddr 148.227.122.245 drop` |
| **nginx** | `deny 148.227.122.245;` |
| pfSense | `148.227.1
| **cloudflare_waf** | `{"description":"Block 148.227.122.245 โ IPDebrief risk score 55","action":"block","filter":{"expression":"ip.src eq 148.227.122.245"}}` |
|---|---|
| **aws_waf** | `{"Addresses":["148.227.122.245/32"],"Description":"IPDebrief risk 55"}` |
---
## Threat Assessment Summary
| Metric | Value |
|---|---|
| **Overall Risk Score** | 55/100 |
| **Abuse Confidence** | Not applicable (no active threats) |
| **DNSBL Lists** | 3/8 |
| **Campaign Correlation** | None |
| **Threat Persistence** | 0 days |
| **Known Malicious Activity** | No |
---
## SOC Analyst Notes
- Risk Level: Moderate โ Elevated risk score without confirmed malicious activity suggests potential for opportunistic abuse rather than confirmed threat actor involvement.
- Action Priority: Monitor rather than block โ Current data indicates no confirmed malicious activity; blocking may impact legitimate residential Starlink users.
- Investigation Focus: Review DNSBL listings for specific reasons; investigate conflicting geolocation signals (Brazil vs. Mexico); monitor neighborhood for correlated abuse patterns.
---
## Related IPs
Three sibling IPs in the same /24 subnet show elevated risk scores:
- 148.227.122.135 (Risk: 40/100)
- 148.227.122.56 (Risk: 40/100)
- 148.227.122.106 (Risk: 40/100)
---
End of Briefing
Source: IPDebrief Intelligence Platform
Generated: 2026-07-29
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Starlink Brazil Serviços de Internet Ltd |
| ASN | AS14593 |
| Network Name | 148.227.122.0 - 148.227.122.255 |
| CIDR Block | 148.227.122.0/24 |
| RIR | ARIN |
| Country | BR |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | customer.brsabra1.isp.starlink.com |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | customer.brsabra1.isp.starlink.com |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 16% | 4 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-22 07:15:25 UTC |
| Last Seen | 2026-07-29 12:24:43 UTC |
| Profile Built | 2026-07-29 12:35:27 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 21 |
Full dossier details are available via our API.