# IPDebrief Intelligence Briefing
IP Address: 189.190.217.141/32
Date: Current Analysis
Classification: Moderate Risk
Risk Score: 65/100
---
## Executive Summary
IP address 189.190.217.141 is classified as a Moderate Risk endpoint (65/100). The address is associated with a mobile carrier network (Telcel/LTE-5G) under the UniNet organization. While the IP exhibits no active threat indicators, geographic discrepancies and a risk score of 65 warrant monitoring. The subnet shows no abuse density, suggesting this may be an isolated high-risk device rather than part of a coordinated malicious infrastructure.
---
## Ownership & Network Context
| Attribute | Value |
|---|---|
| **ASN** | 8151 |
| **Organization** | Gestión de direccionamiento UniNet |
| **Network Block** | 189.190.217.0/24 |
| **RIR** | LACNIC |
| **Geolocation** | Chicago, US (inferred) / Mexico (mobile carrier) |
| **Mobile Carrier** | Telcel (America Movil S.A.B. de C.V.) |
| **Connection Type** | Mobile (LTE/5G) |
| **PTR Hostname** | dsl-141-217-190-189-dynamic.prod-infinitum.com.mx |
Note: Geographic data presents conflicting signals. RIR registration and IP geolocation indicate US/LACNIC, while mobile carrier data (MCC:334, MNC:020) indicates Mexico. This discrepancy may indicate roaming, proxy usage, or data inconsistency.
---
## Threat Assessment
| Indicator | Status |
|---|---|
| Known Attacker | No |
| Spam Source | No |
| Tor Exit Node | No |
| DNSBL Listings | 3 of 8 |
| Blacklist Count | 0 |
| Known Campaigns | None |
| Persistently Malicious | No |
| Open Ports | None (Firewalled) |
The IP shows no active threat indicators. No known malware campaigns, attacker signatures, or spam sources are associated with this address. The 3 DNSBL listings require further investigation.
---
## Neighborhood Analysis
The /24 subnet (189.190.217.0/24) presents a clean profile:
- Abuse Density: 0
- Subnet Classification: Clean
- Threat Siblings: 0
- Active Siblings: 0
This suggests the elevated risk score is isolated to this single IP rather than indicative of broader subnet compromise.
---
## Historical Signals
Observation Count: 18 signals recorded
Recent observation trends show:
- Geographic signals inconsistent between US and Mexico (confidence: 0.30-0.95)
- Ownership signals consistently point to LACNIC/UniNet
- Neighborhood signals show clean classification
- No observed changes in threat profile over the observation period
---
## Technical Observations
| Signal | Value |
|---|---|
| **DNS Resolution** | 1 PTR record (dynamic hostname) |
| **Email Auth** | SPF: Yes, DMARC: No |
| **TLS/HTTP Services** | None detected |
| **Route Stability** | Not stable (0 route changes in 30 days) |
| **RPKI State** | Not reported |
The dynamic PTR hostname pattern (dsl-141-217-190-189-dynamic) is typical of carrier-grade NAT or residential mobile connections.
---
## Recommended Actions
Immediate
1. Increase logging verbosity for traffic from this IP
2. Review recent activity to establish baseline behavior
3. Monitor DNSBL listings (3 of 8) for specific content
Firewall/Blocking Options
iptables:
```bash
iptables -A INPUT -s 189.190.217.141 -j DROP
```
nftables:
```bash
nft add rule inet filter input ip saddr 189.190.217.141 drop
```
nginx:
```nginx
deny 189.190.217.141;
```
pfSense/Cloudflare/AWS WAF: Use provided rule templates with IPDebrief risk score 65
---
## Analyst Notes
- Risk Score 65 is elevated but lacks supporting threat indicators
- Mobile carrier association (Telcel/Mexico) conflicts with US geolocationβinvestigate routing path
- No open ports suggests the IP is either residential, firewalled, or actively defended
- Clean subnet indicates this may be an isolated endpoint requiring monitoring rather than part of a botnet or malicious infrastructure
Recommendation: Monitor for 14-30 days. If no legitimate traffic pattern emerges or threat indicators appear, consider blocking based on organizational policy for moderate-risk mobile endpoints.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Gestión de direccionamiento UniNet |
| ASN | AS8151 |
| Network Name | 189.190.217.0 - 189.190.217.255 |
| CIDR Block | 189.190.217.0/24 |
| RIR | LACNIC |
| Country | MX |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | dsl-141-217-190-189-dynamic.prod-infinitum.com.mx |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | dsl-141-217-190-189-dynamic.prod-infinitum.com.mx |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_8.2p1 Ubuntu-4ubuntu0.13 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-22 01:11:29 UTC |
| Last Seen | 2026-08-13 06:44:21 UTC |
| Profile Built | 2026-07-29 11:54:59 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 22 |
Full dossier details are available via our API.