IPDebrief

177.8.252.89

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

IP INTELLIGENCE BRIEFING: 177.8.252.89/32

SUBJECT: Threat Assessment and Security Recommendations

DATE: Current

SOURCE: IPDebrief Intelligence Platform

---

## EXECUTIVE SUMMARY

IP 177.8.252.89 has been assessed as HIGH RISK with an overall risk score of 80/100. The IP is registered to ISUPER TELECOMUNICACOES INFO LTDA (ASN 263579) in Marialva, Paraná, Brazil. The address is classified as firewalled with no active services, though it exhibits significant threat indicators including multiple DNSBL listings and elevated neighborhood abuse density.

---

## RISK PROFILE

MetricValue
**Overall Risk Score**80/100 (High Risk)
**Reputation**High Risk
**Country**Brazil (BR)
**City**Marialva, Paraná
**ASN**263579
**Organization**ISUPER TELECOMUNICACOES INFO LTDA
**CIDR Block**177.8.252.0/22
**DNSBL Listings**4 of 8 total lists
**Network Classification**Firewalled / No Services
**Operator Score**0.1304 (Minimal)

---

## THREAT INDICATORS

The IP presents multiple threat signals despite being registered as residential:

Notable network associations include 19 DNS entries mapping to hostname 252-089.isuper.com.br, indicating reverse DNS resolution is active despite the IP being classified as residential.

---

## NEIGHBORHOOD ANALYSIS

The /24 subnet contains 6 neighboring IPs with the following risk distribution:

IP AddressRisk ScoreClassification
177.8.252.4040Medium
177.8.252.4155Medium
177.8.252.8855Medium
177.8.252.9155Medium
177.8.252.1090Low
177.8.252.2360Low

Subnet Summary: 4 medium-risk, 2 low-risk neighbors. The elevated density suggests coordinated activity within the block.

---

## OBSERVATION HISTORY

Analysis of 21 historical observations reveals:

---

## RECOMMENDED ACTIONS

Based on the risk profile (80/100), the following security measures are recommended:

IMMEDIATE (Priority: Critical)

Block at Perimeter:

```bash

# iptables

iptables -A INPUT -s 177.8.252.89 -j DROP

# nftables

nft add rule inet filter input ip saddr 177.8.252.89 drop

# nginx

deny 177.8.252.89;

# Cloudflare WAF

{"description": "Block 177.8.252.89 โ€” IPDebrief risk score 80", "action": "block", "filter": {"expression": "ip.src eq 177.8.252.89"}}

# AWS WAF

{"Addresses": ["177.8.252.89/32"], "Description": "IPDebrief risk 80"}

```

MONITORING (Priority: High)

---

## INTELLIGENCE CONTEXT

The IP resides in a subnet with moderate abuse density (14.29%). While the specific address shows no active service banners or open ports, its reputation score and DNSBL presence indicate prior abuse activity. The relationship graph shows 33 associations, predominantly network-level and DNS-based, with no direct organizational or certificate links identified.

Threat Level: HIGH โ€” Block and monitor. Review historical logs for correlated incidents.

---

END OF BRIEFING

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ง๐Ÿ‡ท Brazil
RegionParaná
CityMarialva
Timezoneโ€”
Latitude-23.54
Longitude-51.90

๐Ÿข Ownership & Registration

OrganizationISUPER TELECOMUNICACOES INFO LTDA
ASNAS263579
Network Name213710
CIDR Block177.8.252.0/22
RIRLACNIC
CountryBR
Abuse Contactโ€”

๐ŸŒ DNS Intelligence

PTR252-089.isuper.com.br
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnames252-089.isuper.com.br

๐Ÿ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureResidential
Service PurposeResidential Endpoint
Network TierEnd-User โ€” Residential ISP endpoint
Residential

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
36%
24
routing
19%
12
services
8%
11
ownership
15%
22
reputation
25%
13
geolocation
19%
22
Overall20%914
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-08 05:01:51 UTC
Last Seen2026-06-25 02:24:11 UTC
Profile Built2026-06-25 02:45:18 UTC
Data FreshnessLive
Signal Types20
Total Observations21
๐Ÿ” 20 signal types ยท 21 observations collected
This report is generated from 20+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.