# IP Intelligence Briefing: 168.90.31.176/32
Classification: Moderate Risk
Report Date: 2026-07-29
Analyst: IPDebrief Intelligence Team
## Executive Summary
The IP address 168.90.31.176 was assessed as a moderate-risk endpoint with a risk score of 40. The address is geolocated to Brazil and shows no active service presence, though it carries DNSBL listings indicating prior reputation concerns. The subnet environment is classified as clean with minimal inherited risk.
## Profile Analysis
Geolocation: The endpoint is located in Joaçaba, Santa Catarina state, Brazil (coordinates: -27.16°S, -51.59°W). Geographic consensus is supported by a single source.
Network Classification: The IP is designated as "Firewalled / No Services" with zero open ports detected. No TLS certificates, HTTP responses, or service banners were observed. The address is not classified as a provider, CDN, VPN, proxy, Tor exit node, or hosting service.
Ownership Data: No registrable ownership information was retrieved. ASN, organization name, netname, and RIR registration data were unavailable.
Control Plane: The IP originates from ASN 262417 with BGP prefix 168.90.30.0/23. The route is flagged as unstable. DNSSEC validation is enabled, but the address appears on 2 out of 8 DNSBL lists. Operator score was recorded as 0.1304, labeled as "Minimal."
## Threat Indicators
Reputation Sources: The address carries moderate risk but shows no active threat indicators. Known campaigns, attacker signatures, spam source flags, and Tor exit node status were all negative. Abuse confidence score was not populated.
Historical Observations: Fourteen signal observations were recorded. Recent activity includes:
- Geolocation signals from Brazil (confidence 0.70)
- Network role classification as non-service (confidence 0.30-0.70)
- Subnet abuse density classification as "clean" (confidence 0.40)
- Operator score signals indicating minimal risk (confidence 0.60-0.70)
No malicious behavior patterns were detected in the observation history.
## Relationship Network
The IP maintains DNS associations with hostname "as262417.sc.ultrat.com.br". Forward resolution is confirmed. No additional relationships to organizations, subnets, certificates, or other entities were identified.
## Neighborhood Assessment
The /24 subnet (168.90.31.0/24) contains 256 sibling addresses. Abuse density was measured at 0, and the subnet is classified as "clean." The single neighboring IP (168.90.31.151) carries a risk score of 15, indicating low risk. No threat siblings were identified within the subnet.
## Recommended Security Actions
Based on the risk profile, the following actions are recommended:
- iptables: `iptables -A INPUT -s 168.90.31.176 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 168.90.31.176 drop`
- nginx: `deny 168.90.31.176;`
- pfSense: Block 168.90.31.176/32
- Cloudflare WAF: Block with expression `ip.src eq 168.90.31.176`
- AWS WAF: Add 168.90.31.176/32 to IPSet
## Conclusion
The endpoint 168.90.31.176 presents moderate risk primarily due to DNSBL listings and control plane instability. No active malicious indicators were observed. The clean neighborhood context suggests the address may be associated with legacy reputation issues rather than current threat activity. Recommended mitigation includes blocking the address across perimeter security controls.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Unknown |
| ASN | โ |
| Network Name | โ |
| CIDR Block | โ |
| RIR | โ |
| Country | โ |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | as262417.sc.ultrat.com.br |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | as262417.sc.ultrat.com.br |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Low (30%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-22 13:23:50 UTC |
| Last Seen | 2026-07-29 13:35:46 UTC |
| Profile Built | 2026-07-29 13:43:54 UTC |
| Data Freshness | Live |
| Signal Types | 15 |
| Total Observations | 15 |
Full dossier details are available via our API.