# IP Intelligence Briefing: 177.22.116.206/32
## Executive Summary
The IP address 177.22.116.206 presents a moderate risk profile (score: 40) with no active threat indicators. The address is associated with Brazilian telecommunications infrastructure and has been observed as a residential endpoint. Current intelligence indicates no malicious activity, but the IP should be monitored for behavioral changes.
---
## Profile Overview
IP Address: 177.22.116.206/32
Risk Score: 40 (Moderate Risk)
Reputation: Moderate Risk
Network Classification:
- ASN: 263331 (Netvox Telecomunicacoes LTDA, BR)
- Organization: WN TELECOM LTDA - ME
- CIDR Block: 177.22.116.0/24
- RIR: LACNIC
- Service Purpose: Firewalled / No Services
Geolocation:
- Country: Brazil (BR)
- Region: São Paulo (SP)
- City: Barueri
- Accuracy Radius: 2500 km
---
## Threat Indicators Assessment
Active Threats: None detected
- Known attacker: No
- Tor exit node: No
- Spam source: No
- Blacklist count: 0
- Known campaigns: None
Control Plane Data:
- DNSBL listed: 2 of 8 total lists
- Operator score: 0.1304 (Minimal)
- Route stability: False
- BGP Prefix: 177.22.112.0/21
---
## Network Infrastructure
Service Scan Results:
- Open ports: None detected
- TLS certificates: None
- HTTP services: None
- Reverse DNS (PTR): 177-22-116-206.dyn.wntelecom.net.br
- Forward DNS resolution: Pending confirmation
DNS Configuration:
- No SPF or DMARC records configured
- TXT record count: 0
---
## Neighborhood Analysis
Subnet: 177.22.116.0/24
Abuse Density: 0
Classification: Clean
Total Siblings: 1
Active Siblings: 1
Threat Siblings: 0
Risk distribution across the /24 subnet shows no high or medium-risk peers, indicating this IP exists in a relatively clean network environment.
---
## Observation History (18 Signals)
Timeline: 2026-06-06 through 2026-06-26
Key Observations:
- 2026-06-26: Classified as residential infrastructure
- 2026-06-06: ASN 263331 confirmed; subnet classification as "clean" with zero threat siblings
- Consistent geolocation inferences pointing to Brazil (coordinates: -14.24, -51.93)
Signal Summary:
- No campaign correlations detected
- Zero correlated IPs
- No certificate matches
- No banner analysis matches
---
## Relationships Graph
Total Relationships: 22
- Network Associations: 10 entries linking to network 466164
- DNS Associations: 12 entries pointing to dynamic hostname 177-22-116-206.dyn.wntelecom.net.br
No organizational or certificate-based relationships detected beyond DNS and network infrastructure links.
---
## Recommended Actions
Firewall Rules Generated:
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 177.22.116.206 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 177.22.116.206 drop` |
| nginx | `deny 177.22.116.206;` |
| pfSense | `177.22.116.206/32` |
| Cloudflare WAF | Block with filter expression `ip.src eq 177.22.116.206` |
| AWS WAF | Add to block list with description "IPDebrief risk 40" |
---
## Intelligence Assessment
Current Status: The IP demonstrates moderate risk primarily due to DNSBL presence (2 lists) but lacks active threat indicators. The residential classification and clean neighborhood suggest legitimate endpoint usage, though the DNSBL listings warrant monitoring.
Threat Level: LOW
Recommended Action: Monitor. No immediate blocking required unless specific traffic patterns indicate abuse.
Next Review: Monitor for changes in threat indicators, DNSBL status, or behavioral patterns that may escalate risk profile.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | WN TELECOM LTDA - ME |
| ASN | AS263331 |
| Network Name | 466164 |
| CIDR Block | 177.22.116.0/24 |
| RIR | LACNIC |
| Country | BR |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | 177-22-116-206.dyn.wntelecom.net.br |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 177-22-116-206.dyn.wntelecom.net.br |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Residential |
| Service Purpose | Residential Endpoint |
| Network Tier | End-User โ Residential ISP endpoint |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 13% | 1 | 2 |
| geolocation | 19% | 2 | 2 |
| Overall | 17% | 10 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-11 21:10:17 UTC |
| Last Seen | 2026-06-26 12:01:53 UTC |
| Profile Built | 2026-06-26 12:13:53 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 21 |
Full dossier details are available via our API.