# IP Intelligence Briefing: 177.93.204.67/32
Classification: Moderate Risk | Date: 2026-07-29
## Executive Summary
IP address 177.93.204.67 is a multi-service host belonging to Holistica Provedor Internet Ltda (ASN 53075) with a risk score of 55/100. The IP is geolocated to Irecê, Bahia, Brazil, and is currently listed on three of eight DNS blacklists with high-severity ratings. While the overall subnet (177.93.204.0/24) shows clean abuse density, the specific IP has been observed with active port scans and redirect behavior.
## Ownership and Network Context
| Field | Value |
|---|---|
| Organization | Holistica Provedor Internet Ltda |
| ASN | 53075 |
| CIDR Block | 177.93.192.0/19 |
| Network Name | 229295 |
| Geolocation | Brazil, Bahia, Irecê |
The IP operates as a multi-service host with HTTP (port 80) and SSH (port 22) services enabled. Server banner indicates lighttpd/1.4.39.
## Threat Indicators
- DNSBL Listings: 3 of 8 total lists (high severity)
- Threat Feeds: No active threat indicators
- Campaign Correlation: Zero matches
- Blacklist Status: Listed on multiple sources
## Service and Port Analysis
| Port | Protocol | Service | Status |
|---|---|---|---|
| 80 | TCP | HTTP | Active (302 redirect) |
| 22 | TCP | SSH | Active (dropbear) |
HTTP fingerprinting shows HTTP/1.1 with TTFB of 1011ms. No TLS certificates or HSTS headers detected.
## Neighborhood Assessment
The /24 subnet (177.93.204.0/24) contains three IPs with 0% abuse density:
- 177.93.204.67 (Target): Risk Score 55
- 177.93.204.132: Risk Score 40 (medium risk)
- 177.93.204.199: No risk data available
Network classification is clean with inherited risk of 0.
## Historical Observation Summary
Fourteen observations recorded on 2026-07-29. Key findings:
- Port Scanning: Multiple port scans observed with SSH banner disclosure
- Redirect Behavior: HTTP status code 302 (temporary redirect)
- Geolocation Confidence: 52% confidence for Brazil (Bahia region)
- Ownership Stability: No ownership changes detected
- Threat Persistence: Zero days of persistent malicious activity
## Recommended Actions
1. Monitor SSH Connections: The dropbear SSH server may be used for legitimate access or unauthorized remote control. Implement rate limiting on port 22.
2. DNSBL Review: Investigate the three high-severity blacklist listings to determine if they relate to spam, abuse, or scanning activity.
3. Redirect Analysis: The HTTP 302 redirect behavior warrants investigation to determine if it points to malicious destinations.
4. Neighbor Correlation: Monitor 177.93.204.132 (risk score 40) for coordinated activity, as both IPs share the same network infrastructure.
## Intelligence Assessment
The IP presents moderate risk due to DNSBL listings and active scanning behavior. While the organization appears to be a legitimate internet service provider, the IP's blacklist presence and redirect behavior suggest potential abuse or compromise. No evidence of persistent malicious campaigns or active exploitation. Recommend continued monitoring and review of blacklist removal options.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Holistica Provedor Internet Ltda |
| ASN | AS53075 |
| Network Name | 229295 |
| CIDR Block | 177.93.192.0/19 |
| RIR | LACNIC |
| Country | BR |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Multi-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 443, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | lighttpd/1.4.39 |
| HTTP Title | โ |
| SSH Version | SSH-2.0-dropbear <??bbW?b??;?0?_??curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-gro |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 25% | 1 | 1 |
| reputation | 25% | 1 | 1 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-24 08:18:19 UTC |
| Last Seen | 2026-07-29 22:18:43 UTC |
| Profile Built | 2026-07-29 22:29:41 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.