# IP Intelligence Briefing: 177.93.204.199/32
Date: July 30, 2026
Classification: Low Risk
Status: Monitored
---
## Executive Summary
IP 177.93.204.199 registered to Holistica Provedor Internet Ltda (ASN 53075) presents a low-risk profile with a risk score of 30. The address is geolocated to Irecê, Bahia, Brazil, though geolocation signals show inconsistencies including transit routing through New York. The subnet demonstrates minimal abuse density with two neighboring IPs exhibiting elevated risk scores. No active threat indicators or malicious campaigns were detected during analysis.
---
## Ownership and Network Classification
- Organization: Holistica Provedor Internet Ltda
- ASN: 53075
- Network Block: 177.93.192.0/19
- CIDR: 177.93.204.199/32
- Classification: Residential/Provider infrastructure
- Network Role: Firewalled with no active services detected
The IP demonstrates standard residential or edge provider characteristics with no cloud, CDN, hosting, or proxy indicators. The address maintains stable ownership with no recorded changes.
---
## Geolocation Analysis
- Country: Brazil (BR)
- Region: Bahia
- City: Irecê
- Geolocation Confidence: Moderate (geoConsensus: false, geoPlausible: true)
- RTT Measurement: 175.2ms average (5 probes)
- Distance from Source: 8,456.9 km
Geolocation validation indicates plausible Brazilian positioning, though traceroute analysis revealed transit routing through US networks (Cogent, Comcast). This suggests the IP may be part of an international transit path or edge infrastructure.
---
## Threat Intelligence Indicators
Threat Status: Clean
- Abuse Confidence Score: Not applicable
- Blacklist Status: Listed on 2 of 8 DNSBLs
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Campaign Correlation: None detected
- Threat Persistence: Not persistently malicious
The IP maintains a clean threat profile with no association to known malicious campaigns, attack patterns, or abuse campaigns.
---
## Neighborhood Analysis
The /24 subnet (177.93.204.0/24) shows minimal abuse activity with an abuse density score of 0 and clean classification. Two neighboring IPs require monitoring:
| IP Address | Risk Score | Authority Score | Status |
|---|---|---|---|
| 177.93.204.67 | 55 | 50 | Elevated |
| 177.93.204.132 | 40 | 50 | Moderate |
The analyzed IP (177.93.204.199) remains within the clean segment of this subnet.
---
## Historical Observations
Fifteen observations recorded during the monitoring period. Key temporal signals include:
- Most Recent: July 30, 2026, 11:37 UTC
- Network Signals: Consistent residential/provider classification
- Traceroute: 17 hops with 4 timeouts observed
- Geolocation Variance: One observation indicated New York transit routing (JFK, Cogent)
- Stability: No ownership changes or threat persistence patterns
---
## Recommended Actions
Immediate Action Required: None
Monitoring Recommendations:
- Monitor neighboring IPs (177.93.204.67, 177.93.204.132) for escalation
- Track DNSBL listing status changes
- Continue monitoring for service port opening
Firewall Rule Status: No specific firewall rules generated. The IP presents minimal threat and may be permitted through existing security policies.
---
## Conclusion
IP 177.93.204.199 represents a low-risk residential or edge provider address with no active threat indicators. The subnet exhibits minimal abuse activity. SOC teams may continue standard monitoring without immediate blocking or escalation. The elevated-risk neighboring IPs warrant periodic review to assess subnet-level activity patterns.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Holistica Provedor Internet Ltda |
| ASN | AS53075 |
| Network Name | 229295 |
| CIDR Block | 177.93.192.0/19 |
| RIR | LACNIC |
| Country | BR |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| Closed Ports | 22, 25, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 1 |
| reputation | 0% | 0 | 0 |
| geolocation | 35% | 2 | 2 |
| Overall | 22% | 6 | 6 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-27 09:39:05 UTC |
| Last Seen | 2026-07-30 11:31:09 UTC |
| Profile Built | 2026-07-30 11:46:08 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.