IP INTELLIGENCE BRIEFING
Target IP: 187.190.143.36/32
Classification: Moderate Risk (Score: 50)
Date: Current Analysis Cycle
---
NETWORK OWNERSHIP & GEOLOCATION
The IP address 187.190.143.36 belongs to ASN 22884, operated by TOTAL PLAY TELECOMUNICACIONES, S.A.P.I. DE C.V. The address is allocated within the 187.190.0.0/16 block under LACNIC RIR registration. Geolocation data indicates the IP originates from Irapuato, Guanajuato, Mexico, with a 1200km accuracy radius. The network classification identifies this as a Multi-Service Host infrastructure type.
THREAT POSTURE & RISK INDICATORS
The IP maintains a risk score of 50, categorized as Moderate Risk. No active threat indicators were detected in the current assessment. The IP is not flagged as a known attacker, Tor exit node, proxy, VPN, or spam source. Blacklist enumeration returned zero entries across major threat feeds. DNSBL listing count of 2 out of 8 total lists indicates minimal reputation impact.
INFRASTRUCTURE PROFILE
DNS analysis resolved the IP to rnueva.com.mx with forward confirmation. Email authentication shows SPF is configured, though DMARC is absent. Service enumeration identified port 80 (HTTP) and port 22 (SSH) as open. Server banner detection revealed Apache/2.2.22 (Win32) with mod_aspdotnet/2.2 module. SSH version reported as OpenSSH_5.0. TLS certificate data was not observed.
TEMPORAL BEHAVIOR & PERSISTENCE
Historical analysis across 18 observations shows stable ownership with zero ownership changes detected. No persistent malicious activity was observed. Threat persistence metrics indicate zero threat observation count and zero threat persistence days. The IP is not classified as persistently malicious.
NETWORK CONTEXT & NEIGHBORHOOD
Analysis of the /24 neighborhood (187.190.143.0/24) returned zero abuse density. Classification of the subnet remains clean with no active or threat siblings detected. Risk distribution across neighbors shows zero high, medium, or low risk classifications. The IP inherits no neighborhood-level risk.
RELATED ENTITIES
Relationship mapping identified associations with the parent network 187.190.0.0 - 187.190.255.255. DNS associations consistently resolved to rnueva.com.mx across all relationship queries. No certificate-based relationships were identified.
SECURITY RECOMMENDATIONS
Given the moderate risk score of 50 and the Multi-Service Host classification, the following defensive measures are recommended:
- Firewall: Implement DROP rules for traffic from 187.190.143.36
- Cloudflare WAF: Configure block action with expression: `ip.src eq 187.190.143.36`
- AWS WAF: Add IP 187.190.143.36/32 to blocklist
- nginx: Configure `deny 187.190.143.36;` directive
- pfSense: Add 187.190.143.36/32 to firewall rule set
- nftables: Apply `nft add rule inet filter input ip saddr 187.190.143.36 drop`
---
INTELLIGENCE ASSESSMENT
The IP presents moderate risk characteristics without active malicious indicators. The combination of Multi-Service Host classification, absent TLS certificates, and historical DNSBL listings warrants defensive posture. However, the clean neighborhood classification and absence of threat indicators suggest the risk may be associated with general infrastructure noise rather than active adversarial activity. SOC teams should monitor for changes in threat indicators while maintaining current defensive controls.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | TOTAL PLAY TELECOMUNICACIONES, S.A.P.I. DE C.V. |
| ASN | AS22884 |
| Network Name | 187.190.0.0 - 187.190.255.255 |
| CIDR Block | 187.190.0.0/16 |
| RIR | LACNIC |
| Country | MX |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | rnueva.com.mx |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | rnueva.com.mx |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Multi-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 443, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | Apache/2.2.22 (Win32) mod_aspdotnet/2.2 |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_5.0 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 0% | 0 | 0 |
| Overall | 18% | 5 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-22 19:32:42 UTC |
| Last Seen | 2026-08-01 16:33:22 UTC |
| Profile Built | 2026-08-01 16:55:18 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.