Your IP: 216.73.216.123
๐ค Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.
IP Intelligence Briefing: 189.26.112.85
Date: 2026-06-17
---
**1. Risk Profile**
- Reputation: Low Risk (Risk Score: 25)
- Provider: TELEFÔNICA BRASIL S.A. (ASN 18881)
- Geolocation: Curitiba, Paraná, Brazil (BR)
- Network Role: Mobile IP (TIM S.A., LTE/5G)
- Threat Indicators: No malicious activity detected; not listed in blacklists or threat feeds.
---
**2. Key Observations**
- DNS Associations: Linked to `supermix.static.gvt.net.br` (likely a legitimate domain).
- Control Plane:
- DNSSEC validated.
- 1 DNSBL listing (out of 8 monitored lists).
- BGP prefix: `189.26.0.0/17` (subscribed to by TELEFÔNICA BRASIL S.A.).
- Historical Activity:
- One low-confidence threat feed listing (June 17, 2026).
- Subnet abuse density: "mostly_clean" (abuse density: 1).
---
**3. Network Relationships**
- Same Network: 25 entries (all linked to network `91117`).
- DNS Associations: Repeated ties to `supermix.static.gvt.net.br` (22 instances).
- No Active Neighbors: Subnet `189.26.112.85/24` shows no active or threatening sibling IPs.
---
**4. Recommendations**
- Monitor DNS Activity: Track associations with `supermix.static.gvt.net.br` for anomalies.
- Verify Threat Feed Context: Investigate the low-confidence threat listing to confirm legitimacy.
- No Immediate Action Required: The IPโs low-risk profile and lack of malicious indicators suggest it is benign.
---
Conclusion: 189.26.112.85 is a legitimate mobile IP owned by TIM S.A. (TELEFÔNICA BRASIL S.A.). No evidence of malicious activity is present, but ongoing monitoring is advised for contextual anomalies.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | TELEFÔNICA BRASIL S.A |
| ASN | AS18881 |
| Network Name | 91117 |
| CIDR Block | 189.26.0.0/15 |
| RIR | LACNIC |
| Country | BR |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | supermix.static.gvt.net.br |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | supermix.static.gvt.net.br |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_6.7 |
๐ TLS Certificate
No certificate
Issued by โ
N/A
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 19% | 2 | 2 |
| reputation | 24% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 21% | 9 | 13 |
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
โ Claimed geolocation contradicts RTT physics measurement
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:02 UTC |
| Last Seen | 2026-06-23 02:03:42 UTC |
| Profile Built | 2026-06-23 02:10:32 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
๐ 21 signal types ยท 22 observations collected
This report is generated from 21+ independent intelligence signals including
ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds,
behavioral fingerprinting, and more.
Full dossier details are available via our API.
Full dossier details are available via our API.
โน๏ธ About This Report
All data shown is publicly available network metadata โ IP addresses do not reliably identify individuals.
Assessments are probabilistic and should not be used as sole basis for access control decisions.
To report an issue or request data review, contact admin@ipdebrief.com.