IPDebrief

189.190.217.141

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IPDebrief Intelligence Briefing

IP Address: 189.190.217.141/32

Date: Current Analysis

Classification: Moderate Risk

Risk Score: 65/100

---

## Executive Summary

IP address 189.190.217.141 is classified as a Moderate Risk endpoint (65/100). The address is associated with a mobile carrier network (Telcel/LTE-5G) under the UniNet organization. While the IP exhibits no active threat indicators, geographic discrepancies and a risk score of 65 warrant monitoring. The subnet shows no abuse density, suggesting this may be an isolated high-risk device rather than part of a coordinated malicious infrastructure.

---

## Ownership & Network Context

AttributeValue
**ASN**8151
**Organization**Gestión de direccionamiento UniNet
**Network Block**189.190.217.0/24
**RIR**LACNIC
**Geolocation**Chicago, US (inferred) / Mexico (mobile carrier)
**Mobile Carrier**Telcel (America Movil S.A.B. de C.V.)
**Connection Type**Mobile (LTE/5G)
**PTR Hostname**dsl-141-217-190-189-dynamic.prod-infinitum.com.mx

Note: Geographic data presents conflicting signals. RIR registration and IP geolocation indicate US/LACNIC, while mobile carrier data (MCC:334, MNC:020) indicates Mexico. This discrepancy may indicate roaming, proxy usage, or data inconsistency.

---

## Threat Assessment

IndicatorStatus
Known AttackerNo
Spam SourceNo
Tor Exit NodeNo
DNSBL Listings3 of 8
Blacklist Count0
Known CampaignsNone
Persistently MaliciousNo
Open PortsNone (Firewalled)

The IP shows no active threat indicators. No known malware campaigns, attacker signatures, or spam sources are associated with this address. The 3 DNSBL listings require further investigation.

---

## Neighborhood Analysis

The /24 subnet (189.190.217.0/24) presents a clean profile:

This suggests the elevated risk score is isolated to this single IP rather than indicative of broader subnet compromise.

---

## Historical Signals

Observation Count: 18 signals recorded

Recent observation trends show:

---

## Technical Observations

SignalValue
**DNS Resolution**1 PTR record (dynamic hostname)
**Email Auth**SPF: Yes, DMARC: No
**TLS/HTTP Services**None detected
**Route Stability**Not stable (0 route changes in 30 days)
**RPKI State**Not reported

The dynamic PTR hostname pattern (dsl-141-217-190-189-dynamic) is typical of carrier-grade NAT or residential mobile connections.

---

## Recommended Actions

Immediate

1. Increase logging verbosity for traffic from this IP

2. Review recent activity to establish baseline behavior

3. Monitor DNSBL listings (3 of 8) for specific content

Firewall/Blocking Options

iptables:

```bash

iptables -A INPUT -s 189.190.217.141 -j DROP

```

nftables:

```bash

nft add rule inet filter input ip saddr 189.190.217.141 drop

```

nginx:

```nginx

deny 189.190.217.141;

```

pfSense/Cloudflare/AWS WAF: Use provided rule templates with IPDebrief risk score 65

---

## Analyst Notes

Recommendation: Monitor for 14-30 days. If no legitimate traffic pattern emerges or threat indicators appear, consider blocking based on organizational policy for moderate-risk mobile endpoints.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡²πŸ‡½ Mexico
RegionPuebla
CityPuebla City
Timezoneβ€”
Latitude19.05
Longitude-98.19

🏒 Ownership & Registration

OrganizationGestión de direccionamiento UniNet
ASNAS8151
Network Name189.190.217.0 - 189.190.217.255
CIDR Block189.190.217.0/24
RIRLACNIC
CountryMX
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRdsl-141-217-190-189-dynamic.prod-infinitum.com.mx
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesdsl-141-217-190-189-dynamic.prod-infinitum.com.mx

πŸ” DNS Hygiene

Hygiene Score40% (Fair)
SPFPresent
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureMobile
Service PurposeSingle-Service Host
Network TierUnknown β€” Insufficient routing data to classify
Mobile

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
22sshtcp
Closed Ports25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”
SSH VersionSSH-2.0-OpenSSH_8.2p1 Ubuntu-4ubuntu0.13

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
0%
00
reputation
0%
00
geolocation
0%
00
Overall12%33
Coverage: 3/6 dimensions Β· Data sufficiency: partial
Data CoherenceMostly Consistent (80%) β€” 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Claimed geolocation contradicts RTT physics measurement

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-07-22 01:11:29 UTC
Last Seen2026-08-13 06:44:21 UTC
Profile Built2026-07-29 11:54:59 UTC
Data FreshnessLive
Signal Types22
Total Observations22
πŸ” 22 signal types Β· 22 observations collected
This report is generated from 22+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.