# IPDebrief Intelligence Briefing
Target IP: 179.191.132.119/32
Date: 2026-07-29
Classification: Residential Endpoint
## Executive Summary
The IP address 179.191.132.119 is a residential endpoint registered to Alares Cabo Servicos de Telecomunicacoes S.A. with an overall risk score of 25 (Low Risk). No known malicious activity has been associated with this IP. However, geolocation validation anomalies and a DNSBL listing warrant continued monitoring.
---
## Ownership and Network Information
| Field | Value |
|---|---|
| Organization | Alares Cabo Servicos de Telecomunicacoes S.A. |
| CIDR Block | 179.191.128.0/20 |
| ASN | Not assigned |
| RIR | LACNIC (Brazil) |
| Registration Date | Not available |
---
## Geolocation Analysis
| Field | Value |
|---|---|
| Country | Brazil (BR) |
| Region | Minas Gerais |
| City | Varginha |
| IPType | Residential |
โ ๏ธ GeoValidation Alert: Significant discrepancy between claimed and observed geolocation. The IP is registered to Brazil, but measurements indicate a distance of 9,642 km with an RTT of 140ms. The minimum possible RTT for this distance is 192.8ms, rendering the claimed geolocation implausible. This may indicate:
- Routing anomalies
- Misconfigured geo-logging
- Potential IP spoofing
- Cloud/CDN masquerading as residential
---
## Threat Assessment
| Indicator | Status |
|---|---|
| Risk Score | 25 (Low Risk) |
| Known Attacker | No |
| Tor Exit Node | No |
| Spam Source | No |
| Blacklist Count | 0 |
| DNSBL Listed | 1 of 8 lists |
| Pulsedive Risk | Not available |
| Is Persistently Malicious | No |
Threat Indicators: None detected. No known campaigns, threat feeds, or abuse confidence scores associated with this IP.
---
## Network Behavior
- Infrastructure Type: Residential
- Services Detected: None (no open ports identified)
- DNS Resolution: No PTR records, no forward resolution
- Email Authentication: SPF/DMARC not configured
- Honeypot Hits: 0
- WAF Violations: None recorded
---
## Neighborhood Analysis
- Subnet: 179.191.132.0/24
- Abuse Density: 0
- Neighbor Count: 0
- Risk Distribution: None
- Threat Siblings: 0
The immediate /24 subnet shows no abuse activity or neighboring threat indicators.
---
## Historical Observations
13 observations recorded as of 2026-07-29. Key observations:
- Geolocation signals show inconsistent country data with Brazil consistently reported
- RTT measurements indicate implausible distances
- Ownership signals show zero changes and no persistent malicious behavior
- Network role consistently classified as residential
---
## Relationship Graph
3 relationships identified, all indicating "Same Network" connections to network entity 549111.
---
## Recommended Actions
No immediate security actions recommended based on current risk profile. The IP presents as a standard residential endpoint with minimal threat indicators.
Monitoring Recommendations:
1. Monitor for changes in DNSBL listings
2. Verify if geo-location anomalies persist over time
3. Watch for any new threat indicator associations
---
Analyst Notes: While this IP currently presents low risk, the geolocation validation failure is notable for threat intelligence correlation. The discrepancy between registered and observed location should be considered when analyzing potential spoofing or routing-related activities.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Alares Cabo Servicos de Telecomunicacoes S.A. |
| ASN | โ |
| Network Name | 549111 |
| CIDR Block | 179.191.128.0/20 |
| RIR | LACNIC |
| Country | BR |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Residential |
| Service Purpose | Residential Endpoint |
| Network Tier | End-User โ Residential ISP endpoint |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 1 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-23 01:41:04 UTC |
| Last Seen | 2026-07-29 16:10:39 UTC |
| Profile Built | 2026-07-29 16:22:53 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 16 |
Full dossier details are available via our API.