## IP Intelligence Briefing: 181.173.199.254/32
Classification: Mobile Carrier Infrastructure (Moderate Risk)
Report Generated: [Current Date]
Risk Score: 50/100
---
Executive Summary
IP 181.173.199.254 is a mobile carrier endpoint associated with TELEFONICA MOVIL DE CHILE S.A. (ASN 7418). The IP belongs to the 181.172.0.0/15 CIDR block and is classified as a mobile device with no active services. While the IP shows minimal operator-level risk (0.1304), it appears on 2 of 8 DNSBL lists and received a risk score of 50, warranting monitoring. No active malicious campaigns or persistent threats observed.
---
Infrastructure Profile
| Attribute | Value |
|---|---|
| **ASN** | 7418 (TELEFONICA MOVIL DE CHILE S.A.) |
| **CIDR Block** | 181.172.0.0/15 |
| **Geolocation** | US, New York, NY |
| **Network Role** | Mobile Carrier |
| **Service Status** | Firewalled / No Services |
| **Open Ports** | None detected |
---
Threat Intelligence
Current Risk Indicators:
- Blacklist Status: Listed on 2 of 8 DNSBL feeds
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Campaign Activity: None detected
- Abuse Confidence: Not available
Temporal Analysis:
- Observation History: 19 signals recorded (2026-07-30 to 2026-07-31)
- Ownership Changes: 0
- Threat Persistence: 0 days
- Route Stability: Unstable (0 changes in 30-day period)
- Persistent Malicious Activity: False
---
Network Context
Subnet Analysis (181.173.199.0/24):
- Abuse Density: 0%
- Classification: Clean
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 0
- High/Medium/Low Risk Neighbors: 0/0/0
DNS Relationships:
- PTR Record: 181-173-199-254.bam.movistar.cl
- Associated Domain: movistar.cl
- Email Authentication: SPF and DMARC configured
---
Recommended Actions
Firewall Rules (for immediate implementation):
```bash
# iptables
iptables -A INPUT -s 181.173.199.254 -j DROP
# nftables
nft add rule inet filter input ip saddr 181.173.199.254 drop
# nginx
deny 181.173.199.254;
# pfSense
181.173.199.254/32
# Cloudflare WAF
ip.src eq 181.173.199.254 (action: block)
# AWS WAF
Addresses: 181.173.199.254/32
```
Monitoring Recommendations:
1. Monitor for port scan activity (signal_type_id: 8 observed 2026-07-30)
2. Track DNSBL status changes (currently 2/8 lists)
3. Verify geolocation consistency (reported US-NY despite Chilean carrier)
---
Intelligence Assessment
The IP presents moderate risk primarily due to DNSBL listings and unstable routing characteristics. The mobile carrier classification and lack of open services suggest infrastructure use rather than direct attack vectors. No evidence of active campaigns or coordinated malicious activity. Recommend blocking at perimeter but continue monitoring for emerging threat indicators.
Confidence Level: Medium
Last Updated: 2026-07-31
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | TELEFONICA MOVIL DE CHILE S.A. |
| ASN | AS7418 |
| Network Name | 181.172.0.0 - 181.173.255.255 |
| CIDR Block | 181.172.0.0/15 |
| RIR | LACNIC |
| Country | CL |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 181-173-199-254.bam.movistar.cl |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 181-173-199-254.bam.movistar.cl |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 45% | 2 | 3 |
| routing | 22% | 1 | 1 |
| services | 31% | 2 | 2 |
| ownership | 45% | 2 | 3 |
| reputation | 22% | 1 | 2 |
| geolocation | 0% | 0 | 0 |
| Overall | 27% | 8 | 11 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-29 22:49:54 UTC |
| Last Seen | 2026-07-31 19:32:30 UTC |
| Profile Built | 2026-07-31 19:33:31 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 21 |
Full dossier details are available via our API.