IPDebrief

177.189.14.105

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# INTELLIGENCE BRIEFING: IP 177.189.14.105

## EXECUTIVE SUMMARY

IP address 177.189.14.105 is a low-risk residential telecommunications endpoint located in São Paulo, Brazil, operated by TELEFÔNICA BRASIL S.A. (ASN 27699). The IP is firewalled with no active services, presents minimal threat indicators, and exhibits stable operational characteristics typical of residential broadband infrastructure.

## NETWORK OWNERSHIP & GEOSPIES

Organization: TELEFÔNICA BRASIL S.A

ASN: 27699

CIDR Block: 177.188.0.0/15

Location: São Paulo, SP, Brazil (BR)

Registration: RIR: LACNIC

The IP resolves to a residential DSL hostname (177-189-14-105.dsl.telesp.net.br), indicating a consumer-grade telecommunications connection rather than infrastructure hosting.

## THREAT ASSESSMENT

Risk Score: 25 / 100 (Low Risk)

Abuse Confidence: Not scored

Threat Indicators: None detected

Blacklist Status: Listed on 1 DNSBL out of 8 queried lists

Campaign Association: None

Campaign Likelihood: None

No threat feed matches, known attacker indicators, spam source flags, or Tor exit node characteristics observed.

## NETWORK ROLE & SERVICES

Connection Type: Firewalled / No Services

Open Ports: None detected

Active Services: None

Infrastructure Classification: Residential ISP endpoint

Cloud/CDN/Proxy: Not detected

The endpoint does not host public-facing services and appears configured for inbound traffic filtering.

## OBSERVATION HISTORY

Total Observations: 22

Recent Activity: Signals observed as recent as 2026-06-26

Geolocation Confidence: Moderate (0.52) - Brazil coordinates inferred

Routing Validation: ICMP blocked; geolocation validation unable to complete

Threat Persistence: Zero days of persistent malicious behavior

Classification Stability: Subnet classified as "mostly_clean" with inherited risk score of 2

Historical signals show consistent geolocation to Brazil and stable operational patterns with no escalation in threat signals over the observation period.

## NEIGHBORHOOD ANALYSIS

Subnet: 177.189.14.105/24

Abuse Density: 1 (Low)

Classification: Mostly Clean

Total Siblings: 1

Active Siblings: 1

Threat Siblings: 1

The /24 subnet exhibits minimal abuse density with a single active sibling IP. One threat-related sibling detected within the subnet, suggesting potential localized abuse activity that may warrant contextual awareness.

## RELATIONSHIP GRAPH

Total Relationships: 31

Primary Associations:

Relationships indicate standard telecommunications network topology with DNS reverse resolution associations.

## RECOMMENDED ACTIONS

Firewall Rules: No restrictive rules required for this IP based on current risk profile

Monitoring Priority: Standard - No elevated threat activity detected

Block List: Not recommended for blocking; low-risk telecommunications endpoint

## SOC ANALYST NOTES

This IP represents a standard residential broadband connection from a major Brazilian telecommunications provider. The low risk score (25/100), absence of threat indicators, and residential service classification indicate this is not a threat actor endpoint. However, the presence of one threat sibling in the /24 subnet suggests SOC teams should monitor for potential lateral abuse activity within the broader 177.189.14.0/24 subnet. No immediate defensive action required; maintain standard monitoring protocols.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ง๐Ÿ‡ท Brazil
RegionSP
CitySão Paulo
Timezoneโ€”
Latitude-23.55
Longitude-46.64

๐Ÿข Ownership & Registration

OrganizationTELEFÔNICA BRASIL S.A
ASNAS27699
Network Name189195
CIDR Block177.188.0.0/15
RIRLACNIC
CountryBR
Abuse Contactโ€”

๐ŸŒ DNS Intelligence

PTR177-189-14-105.dsl.telesp.net.br
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnames177-189-14-105.dsl.telesp.net.br

๐Ÿ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown โ€” Insufficient routing data to classify
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
24
routing
13%
11
services
15%
22
ownership
19%
22
reputation
22%
13
geolocation
27%
23
Overall20%1015
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-12 03:43:02 UTC
Last Seen2026-06-26 14:50:01 UTC
Profile Built2026-06-26 14:57:03 UTC
Data FreshnessLive
Signal Types20
Total Observations20
๐Ÿ” 20 signal types ยท 20 observations collected
This report is generated from 20+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.