# IP Intelligence Briefing: 187.76.211.90/32
Date: 2026-07-31
Classification: Moderate Risk
---
## Executive Summary
IP address 187.76.211.90, assigned to ASN 7738 (V tal) under the 187.76.0.0/16 CIDR block in Brazil, presents a moderate risk profile (score 50). Geolocation data indicates the address originates from Betim, Minas Gerais. The IP exhibits no active threat indicators, no service exposure, and no evidence of malicious behavior. Neighborhood analysis revealed zero adjacent IPs with threat activity.
## Technical Profile
Ownership & Network:
- ASN: 7738 (V tal)
- Organization: V tal
- Network: 187.76.0.0/16 (LACNIC registered)
- CIDR Block: 187.76.211.90/24
Geolocation:
- Country: Brazil (BR)
- Region: Minas Gerais
- City: Betim
- Coordinates: -19.9644, -44.1969 (maxmind-geolite2-city)
- Accuracy Radius: 2,500 km
Network Characteristics:
- Network Role: Firewalled / No Services
- Open Ports: None detected
- DNS Resolution: No PTR records, no forward resolution
- Service Purpose: Firewalled / No Services
Threat Assessment:
- Risk Score: 50 (Moderate Risk)
- Abuse Confidence Score: N/A
- Blacklist Count: 0
- Threat Feeds: None matched
- Known Campaigns: None
- Is Tor Exit: No
- Is Known Attacker: No
- Is Spam Source: No
Control Plane:
- Route Stability: False
- Route Changes (30d): 0
- DNSSEC Valid: Yes
- Operator Score: 0.1304 (Minimal)
- DNSBL Listed: 2 of 8 total lists
- BGP Prefix: 187.76.192.0/18 (Origin ASN 7738)
## Observation History
Analysis of 10 historical observations from 2026-07-31 revealed:
- Ownership signals consistently identified ASN 7738/V tal with 0.95 confidence
- Geolocation signals confirmed Brazil with confidence levels ranging from 0.52 to 0.70
- Operator classification remained "Minimal" across observations
- No threat persistence indicators detected
- No persistent malicious behavior observed
## Relationship Analysis
Two relationships were identified, both of type "Same Network" referencing network identifier 514650. No external relationships to hostnames, organizations, or SSL certificates were discovered.
## Neighborhood Assessment
Subnet 187.76.211.90/24 analysis returned:
- Neighbor Count: 0
- Risk Distribution: High: 0, Medium: 0, Low: 0
- Abuse Density: 0
- Active Threat Siblings: 0
The subnet exhibits no adjacent IPs with malicious activity.
## Recommended Actions
Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 187.76.211.90 -j DROP
# nftables
nft add rule inet filter input ip saddr 187.76.211.90 drop
# nginx
deny 187.76.211.90;
# pfSense
187.76.211.90/32
```
Cloudflare WAF:
```json
{
"description": "Block 187.76.211.90 โ IPDebrief risk score 50",
"action": "block",
"filter": {"expression": "ip.src eq 187.76.211.90"}
}
```
AWS WAF:
```json
{
"Addresses": ["187.76.211.90/32"],
"Description": "IPDebrief risk 50"
}
```
## Intelligence Conclusion
IP 187.76.211.90 demonstrates a moderate risk profile primarily driven by network classification rather than active threat indicators. The address shows no evidence of malicious activity, with zero blacklist matches and no threat feed correlations. The subnet environment exhibits no adjacent malicious activity. While the risk score of 50 warrants monitoring, current data does not support immediate blocking without corroborating threat intelligence. Recommended approach: Monitor for service exposure and threat indicator emergence, while maintaining standard defensive posture against the IP address.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | V tal |
| ASN | AS7738 |
| Network Name | 514650 |
| CIDR Block | 187.76.0.0/16 |
| RIR | LACNIC |
| Country | BR |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-30 17:11:46 UTC |
| Last Seen | 2026-08-01 16:33:22 UTC |
| Profile Built | 2026-07-31 03:36:50 UTC |
| Data Freshness | Live |
| Signal Types | 12 |
| Total Observations | 12 |
Full dossier details are available via our API.