# IP Intelligence Briefing: 179.189.196.210
## Executive Summary
IP address 179.189.196.210 presents a Moderate Risk profile (55/100) with no active threat indicators. The IP is associated with NovaNet Provedor e Web Ltda (AS52626) in Brazil and operates in a mixed-risk neighborhood. Current assessment indicates firewalled status with no exposed services.
## Technical Profile
Ownership & Classification:
- Organization: NovaNet Provedor e Web Ltda
- ASN: 52626
- Network Block: 179.189.192.0/21
- RIR: LACNIC
- Classification: Firewalled / No Services
Geolocation:
- Country: Brazil (BR)
- Region: PA (Amazonas)
- City: Novo Progresso
- Geo-Validation: Plausible with 5 probe measurements
Network Services:
- Open Ports: None detected
- TLS Certificates: None
- HTTP Services: None
- DNS PTR: 210.196.189.179.novanetnp.net.br
## Threat Assessment
Risk Indicators:
- Risk Score: 55/100 (Moderate)
- Abuse Confidence Score: Not available
- Blacklist Count: 0
- DNSBL Listings: 3 of 8 lists
- Campaign Correlation: None detected
- Known Attacker: No
- Spam Source: No
Control Plane:
- BGP Prefix: 179.189.196.0/23
- Route Stability: Unstable (flagged)
- RPKI State: Not available
- DNSSEC: Valid
## Neighborhood Context (179.189.196.0/24)
The /24 subnet exhibits elevated abuse activity:
- Total Neighbors: 25
- Abuse Density: 0.04 (4%)
- Risk Distribution: 1 High, 21 Medium, 3 Low
- Notable High-Risk Neighbors: 179.189.196.74 (80), 179.189.196.27/41/45 (70)
## Historical Observations
Analysis of 21 historical observations reveals:
- Consistent ASN attribution to AS52626 since April 2013
- Recent operator scores indicating minimal control plane concerns
- No significant risk trajectory changes observed
- Ownership stability maintained
## Recommended Actions
Immediate:
- Increase logging verbosity for traffic from this IP
- Monitor for any service emergence or behavioral changes
Firewall Mitigation Rules:
```
iptables: iptables -A INPUT -s 179.189.196.210 -j DROP
nftables: nft add rule inet filter input ip saddr 179.189.196.210 drop
nginx: deny 179.189.196.210;
Cloudflare WAF: Block 179.189.196.210 โ IPDebrief risk score 55
AWS WAF: Addresses: 179.189.196.210/32
```
Operational Notes:
- Block recommendation based on elevated risk score (55/100)
- Consider context with neighborhood abuse density when implementing rules
- No immediate evidence of active malicious activity, but monitoring recommended due to neighborhood context
---
*Report generated from IPDebrief intelligence data. All recommendations should be validated against organizational security policies and combined with additional threat intelligence signals before implementation.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | NovaNet Provedor e Web Ltda |
| ASN | AS52626 |
| Network Name | 200671 |
| CIDR Block | 179.189.192.0/21 |
| RIR | LACNIC |
| Country | BR |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | 210.196.189.179.novanetnp.net.br |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 210.196.189.179.novanetnp.net.br |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 13% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 19% | 10 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-10 22:17:22 UTC |
| Last Seen | 2026-06-26 04:39:53 UTC |
| Profile Built | 2026-06-26 04:46:31 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 20 |
Full dossier details are available via our API.