# IP INTELLIGENCE BRIEFING: 179.43.29.137/32
Classification: LOW RISK
Report Date: Current Analysis
Analyst: IPDebrief Intelligence Team
---
## EXECUTIVE SUMMARY
IP address 179.43.29.137/32 presents as a low-risk address with minimal threat indicators. Current risk assessment scores 25/100 (Low Risk). No active malicious behavior, known campaigns, or attacker indicators detected. The IP exhibits geolocation inconsistencies requiring monitoring but currently shows no evidence of abuse.
---
## RISK PROFILE
| Metric | Value |
|---|---|
| Risk Score | 25 (Low) |
| Provider Score | 0 |
| Authority Score | 0 |
| Abuse Confidence | None |
| Known Attacker | No |
| Spam Source | No |
| Tor Exit Node | No |
| DNSBL Listed | 1/8 lists |
| Persistently Malicious | No |
---
## OWNERSHIP & GEOLOCATION
Control Plane Data:
- Origin ASN: 270851
- BGP Prefix: 179.43.29.0/24
- RIR Registry: LACNIC
- Route Stability: Not stable
Geolocation Discrepancy Detected:
- Profile: US (New York, US-NY)
- Historical Observations: Brazil (São Paulo, BR)
- PTR Hostname: 179-43-29-137.mgenetwork.com.br
- Domain Extension: .com.br (Brazilian)
The geolocation inconsistency between profile and historical signals warrants ongoing validation. The .com.br domain and MGE NETWORK EIRELI organization reference from historical data suggest Brazilian operational context.
---
## NETWORK SERVICES & THREAT INDICATORS
Services Analysis:
- Open Ports: None detected
- Service Purpose: Firewalled / No Services
- TLS Certificates: None
- HTTP Services: None
Threat Indicators:
- Known Campaigns: None
- Threat Feeds: None
- Blacklist Count: 0
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: 0
---
## NETWORK RELATIONSHIPS
DNS Associations:
- Primary Hostname: 179-43-29-137.mgenetwork.com.br
- Forward Resolution Count: 1
- Domain: mgenetwork.com.br
Relationship Graph: 2 DNS associations (same hostname duplicated)
---
## NEIGHBORHOOD ANALYSIS
Subnet: 179.43.29.0/24
- Active Neighbors: 0
- Abuse Density: 0
- Threat Siblings: 0
- Risk Distribution: None detected
The /24 subnet shows no adjacent risk indicators, suggesting this IP operates in isolation or as a single endpoint.
---
## OBSERVATION HISTORY
Total Observations: 14 signals recorded
Recent Signal Trends:
- ASN/Ownership: Historical data shows MGE NETWORK EIRELI (Brazil)
- Geolocation: Mixed signals (US vs Brazil) with confidence scores varying 0.12-0.95
- Subnet Classification: Recently marked "clean" with inherited risk 0
- Operator Score: 0.2609 (Basic)
The 14 observations indicate active monitoring with no escalating threat patterns.
---
## SECURITY ACTIONS & RECOMMENDATIONS
Current Risk Score: 25 (Low)
Recommended Actions:
- No immediate blocking required
- Monitor for geolocation consistency
- Continue DNSBL monitoring (1/8 lists)
- Standard traffic filtering applies
Firewall Rules: None generated due to low risk profile
---
## THREAT INTELLIGENCE NARRATIVE
IP 179.43.29.137/32 represents a low-risk endpoint with no active malicious indicators. The address resolves to mgenetwork.com.br with Brazilian domain context, though geolocation signals show US-NY placement—this discrepancy should be validated. The subnet demonstrates zero abuse density and no neighboring threats.
Key Risk Factors:
- Minor DNSBL presence (1 of 8 lists)
- Geolocation signal inconsistency (US vs Brazil)
Mitigating Factors:
- No open ports or services detected
- No known attack campaigns
- No historical malicious activity
- No persistent threat indicators
SOC Analyst Guidance: Treat as benign traffic with standard filtering. Monitor for geolocation consistency and DNSBL status changes. No immediate blocking or escalation required.
---
END OF BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | MGE NETWORK EIRELI |
| ASN | AS270851 |
| Network Name | 386958 |
| CIDR Block | 179.43.28.0/22 |
| RIR | LACNIC |
| Country | BR |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR | 179-43-29-137.mgenetwork.com.br |
| Forward Confirmed | Yes — FCrDNS verified |
| Forward Hostnames | 179-43-29-137.mgenetwork.com.br |
🔐 DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 — Basic operator with some routing infrastructure |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS270851 |
| Network Prefix | 179.43.29.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-07 06:27:20 UTC |
| Last Seen | 2026-08-27 02:14:30 UTC |
| Profile Built | 2026-08-29 06:30:41 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 21 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 179.43.29.137
Who owns the IP address 179.43.29.137?
179.43.29.137 is registered to MGE NETWORK EIRELI. The address falls within the 179.43.28.0/22 network block. Registration is held at LACNIC.
Where is 179.43.29.137 located?
Geolocation data places 179.43.29.137 in São Paulo, São Paulo, Brazil. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 179.43.29.137 malicious or safe?
179.43.29.137 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 179.43.29.137?
The reverse DNS (PTR) record for 179.43.29.137 is 179-43-29-137.mgenetwork.com.br. This hostname is forward-confirmed, meaning it resolves back to the same address.