# IP INTELLIGENCE BRIEFING: 148.227.83.37/32
Classification: Moderate Risk
Date of Analysis: Current
Assigned Risk Score: 40/100
---
## EXECUTIVE SUMMARY
IP address 148.227.83.37 is associated with Starlink Brazil's telecommunications infrastructure (ASN 14593). The IP presents a moderate risk profile (score 40) primarily influenced by neighborhood context rather than direct malicious activity. No active threat indicators, open services, or known campaign associations were identified. The IP is classified as provider infrastructure with firewalled services and no publicly accessible endpoints.
---
## OWNERSHIP AND GEOLOCATION
| Field | Value |
|---|---|
| **Organization** | Starlink Brazil Serviços de Internet Ltda |
| **ASN** | 14593 |
| **Country** | Brazil (BR) |
| **Region** | Federal District |
| **City** | Brasília |
| **RIR** | ARIN |
| **CIDR Block** | 148.227.82.0/23 (BGP prefix) |
| **Registration Date** | Not available |
Geolocation Confidence: GeoPlausible = true, GeoConsensus = true, Accuracy Radius: 3,750 km
---
## NETWORK CLASSIFICATION
| Attribute | Status |
|---|---|
| **Provider** | Yes (Starlink Brazil) |
| **Infrastructure Type** | Firewalled / No Services |
| **Connection Type** | Not determined |
| **CDN/Cloud/Proxy** | Negative |
| **Tor Exit Node** | Negative |
| **Known Attacker** | Negative |
| **Spam Source** | Negative |
| **Blacklist Count** | 0 |
| **DNSBL Listed** | 2 of 8 total lists |
---
## THREAT INDICATORS
Current Threat Status: None Detected
| Indicator | Finding |
|---|---|
| **Abuse Confidence Score** | Not available |
| **Threat Feeds** | Empty |
| **Known Campaigns** | None |
| **Cert Matches** | 0 |
| **Banner Matches** | 0 |
| **Correlated IPs** | 0 |
Threat Persistence: 0 days
Malicious Activity Observed: 0 events
---
## DNS AND SERVICES
| Metric | Value |
|---|---|
| **PTR Hostnames** | customer.brsabra1.isp.starlink.com |
| **Forward Resolution** | customer.brsabra1.isp.starlink.com |
| **Forward Confirmed** | No |
| **Open Ports** | None |
| **TLS Certificate** | None |
| **HTTP Title** | None |
| **Email Auth** | SPF: Yes, DMARC: Yes |
DNSSEC: Valid
CAA Records: Present (3 issuers)
---
## NEIGHBORHOOD ANALYSIS (148.227.83.0/24)
| Metric | Value |
|---|---|
| **Abuse Density** | 0.2857 (28.57%) |
| **Classification** | Mixed |
| **Total Siblings** | 7 |
| **Active Siblings** | 3 |
| **Threat Siblings** | 2 |
| **Risk Distribution** | 4 Medium, 6 Low, 0 High |
Notable Neighbors:
- 148.227.83.17 (Risk: 55, Authority: 50)
- 148.227.83.99 (Risk: 40, Authority: 50)
- 148.227.83.159 (Risk: 40, Authority: 50)
---
## OBSERVATION HISTORY
Total Observations: 21 signals recorded
Recent Activity (June 2026):
- June 22, 2026 16:53: Operator score 0.1 (Minimal), 8 max signals, 1 signal active
- June 17, 2026 12:55: Operator score 0.2174 (Minimal), 8 max signals, 3 signals active
- June 17, 2026 12:54: DNS resolution confirmed to starlink.com (CAA records present)
- June 17, 2026 12:54: Geolocation inference: Brasília, BR (confidence 0.28)
Temporal Stability:
- Ownership Changes: 0
- Threat Observation Count: 0
- Persistently Malicious: No
---
## RELATIONSHIP GRAPH
Total Relationships: 32 identified
Primary Relationship Types:
- Same Network: 148.227.83.0 - 148.227.83.255 (27+ instances)
- Additional network-level associations identified
---
## RECOMMENDED SECURITY ACTIONS
Risk-Based Recommendation: Monitor / Block Based on Context
| Platform | Recommended Action |
|---|---|
| **iptables** | `iptables -A INPUT -s 148.227.83.37 -j DROP` |
| **nftables** | `nft add rule inet filter input ip saddr 148.227.83.37 drop` |
| **nginx** | `deny 148.227.83.37;` |
| **pfSense** | Block 148.227.83.37/32 |
| **Cloudflare WAF** | Block with expression: `ip.src eq 148.227.83.37` |
| **AWS WAF** | Add address 148.227.83.37/32 to rule set |
Contextual Note: While the IP presents a moderate risk score, it is infrastructure associated with a legitimate telecom provider. Blocking may impact legitimate connectivity. Review against organizational requirements before implementing.
---
## INTELLIGENCE CONCLUSION
IP 148.227.83.37 represents Starlink Brazil provider infrastructure with no direct malicious indicators. The moderate risk classification stems from neighborhood abuse density (28.57%) and sibling IP activity rather than the IP's own behavior. The subnet shows mixed risk characteristics with 2 threat-sibling IPs out of 7 total siblings.
Recommended Handling: Monitor traffic patterns. If organizational policy requires provider IP filtering, implement blocking with awareness of potential impact on legitimate Starlink connectivity. No immediate threat response required absent additional contextual intelligence.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Starlink Brazil Serviços de Internet Ltd |
| ASN | AS14593 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | customer.brsabra1.isp.starlink.com |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | customer.brsabra1.isp.starlink.com |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 15% | 1 | 2 |
| geolocation | 30% | 2 | 3 |
| Overall | 19% | 10 | 14 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:45 UTC |
| Last Seen | 2026-06-22 16:53:19 UTC |
| Profile Built | 2026-06-22 17:01:59 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 23 |
Full dossier details are available via our API.