# IP Intelligence Briefing: 179.189.196.20
## Executive Summary
IP address 179.189.196.20 is registered to NovaNet Provedor e Web Ltda (ASN 52626) in Novo Progresso, Brazil. The IP carries a moderate risk score of 55/100 and is listed on 3 out of 8 DNSBLs with high-severity listings observed in recent monitoring. The address presents a mixed-risk profile with elevated neighborhood abuse density (0.3043) and 7 threat siblings within the /24 subnet. Recommended action: implement monitoring and consider blocking based on organizational risk tolerance.
## Ownership and Geolocation
- Organization: NovaNet Provedor e Web Ltda
- ASN: 52626
- CIDR Block: 179.189.192.0/21
- Country: Brazil (BR)
- City: Novo Progresso
- RIR Registration: LACNIC
## Network Classification
- Service Purpose: Firewalled / No Services
- Not classified as: Cloud, CDN, VPN, Proxy, Tor, Hosting, Mobile, Residential
- BGP Prefix: 179.189.196.0/23
- Route Stability: Unstable (route changes observed in last 30 days)
## Threat Indicators
- Risk Score: 55/100 (Moderate Risk)
- DNSBL Listings: 3 of 8 total lists
- Blacklist Count: 0
- Known Attacker: No
- Spam Source: No
- Tor Exit: No
- Abuse Confidence Score: Not available
## Neighborhood Analysis (/24 Subnet)
- Total Siblings: 23
- Active Siblings: 8
- Threat Siblings: 7
- Abuse Density: 0.3043
- Subnet Classification: Mixed
- Highest Risk Neighbor: 179.189.196.74 (Risk Score: 80)
- Risk Distribution: High: 1, Medium: 21, Low: 3
## DNS Resolution
- PTR Record: 20.196.189.179.novanetnp.net.br
- Forward Resolution: Inconsistent (forward confirmed: false)
- Email Authentication: No SPF, No DMARC records
- Domain: net.br
## Historical Observations
Analysis of 18 historical observations reveals:
- Recent blacklist activity with high-severity listings observed
- DNSSEC validation present but no RRSIG records
- Persistent subnet-level threat signals with 7 threat-sibling IPs
- Ownership stability: 0 changes observed
- No persistent malicious behavior detected
## Recommended Security Actions
Monitoring
- Increase logging verbosity and review recent activity from this IP
- Monitor for pattern correlation with other subnet addresses
Firewall Rules
```bash
# iptables
iptables -A INPUT -s 179.189.196.20 -j DROP
# nftables
nft add rule inet filter input ip saddr 179.189.196.20 drop
# nginx
deny 179.189.196.20;
# pfSense
179.189.196.20/32
```
Cloud WAF Rules
Cloudflare WAF: Block 179.189.196.20 โ IPDebrief risk score 55
AWS WAF: Add 179.189.196.20/32 to blocklist with description "IPDebrief risk 55"
## Relationship Graph
- Network Association: Multiple links to network 200671
- DNS Association: 17 links to hostname 20.196.189.179.novanetnp.net.br
- No external organization or certificate relationships detected
## Assessment
This IP represents a moderate-risk infrastructure address from a Brazilian hosting provider. The presence of 7 threat siblings in the /24 subnet and multiple DNSBL listings suggests potential abuse activity. While no specific threat campaigns have been attributed to this IP, the neighborhood context warrants defensive positioning. Recommend implementing monitoring initially, then consider blocking based on organizational risk tolerance and correlation with other security signals.
*Report generated: [Current Date] | Data Source: IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | NovaNet Provedor e Web Ltda |
| ASN | AS52626 |
| Network Name | 200671 |
| CIDR Block | 179.189.192.0/21 |
| RIR | LACNIC |
| Country | BR |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | 20.196.189.179.novanetnp.net.br |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 20.196.189.179.novanetnp.net.br |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 15% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 15% | 2 | 2 |
| reputation | 13% | 1 | 2 |
| geolocation | 19% | 2 | 2 |
| Overall | 14% | 9 | 10 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-11 02:50:44 UTC |
| Last Seen | 2026-06-26 06:48:16 UTC |
| Profile Built | 2026-06-26 06:56:16 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.