IPDebrief

189.28.69.85

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# THREAT INTELLIGENCE BRIEFING

Target IP: 189.28.69.85/32

Date: 2026-07-26

Classification: LOW RISK / DEFENSIVE MONITORING

---

## EXECUTIVE SUMMARY

IP 189.28.69.85 is a low-risk infrastructure address belonging to Tigo (ASN 27882) in Bolivia. The IP demonstrates minimal threat characteristics with a risk score of 25. However, it is listed on one of eight DNS-based blacklists, warranting continued monitoring. No active malicious indicators, open services, or known campaign associations were detected.

---

## NETWORK CLASSIFICATION & OWNERSHIP

---

## THREAT INDICATORS

IndicatorStatus
Risk Score25 (Low Risk)
DNSBL Listings1 of 8 (High Severity)
Tor Exit NodeNo
Known AttackerNo
Spam SourceNo
Campaign AssociationNone Detected

Observation: The IP was rate-limited (HTTP 429) during recent observation, suggesting potential automated access attempts. One DNS blacklist listing with "high" severity was recorded during the 2026-07-26 observation window.

---

## NEIGHBORHOOD ANALYSIS

Subnet: 189.28.69.0/24

Abuse Density: 0.25 (Low/Moderate)

Classification: Mostly Clean

Sibling IP Assessment:

Assessment: The subnet maintains a stable, low-abuse profile with only one threat-sibling IP. The overall neighborhood risk is not elevated.

---

## OBSERVATION HISTORY

---

## SECURITY RECOMMENDATIONS

Action Priority: LOW

1. Monitoring: Maintain passive monitoring on this IP. The single DNSBL listing warrants awareness but does not indicate immediate threat.

2. Allow Rule: No blocking required. Traffic may originate from legitimate Tigo infrastructure.

3. Rate Limiting: The HTTP 429 response indicates the source may attempt automated access. Consider applying standard rate-limiting policies if traffic originates from this range.

4. Block Consideration: Only recommended if the specific DNSBL listing is confirmed relevant to organizational security posture.

---

Analyst Notes: This IP represents legitimate telecommunications infrastructure with minimal threat characteristics. The blacklist listing and rate-limit response are typical of defensive infrastructure responses rather than active malicious behavior. No immediate containment actions required.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇺🇸 United States
RegionUS-NY
CityNew York
TimezoneAmerica/New_York
Latitude-17.78
Longitude-63.18

🏢 Ownership & Registration

Organizationadmin-ipbroker
ASNAS27882
Network NameBO-TIGO-202304
CIDR Block189.28.64.0/20
RIRLACNIC
CountryBO
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRLPZ-189-28-68-00085.tigo.bo
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)
Forward HostnamesLPZ-189-28-68-00085.tigo.bo

🔐 DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown — Insufficient routing data to classify
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Server—
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS27882
Network Prefix189.28.69.0/24
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
0%
00
services
0%
00
ownership
0%
00
reputation
25%
11
geolocation
0%
00
Overall8%22
Coverage: 2/6 dimensions · Data sufficiency: partial
Data CoherenceMostly Consistent (80%) — 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Geo sources disagree on country: BR, US

📅 Observation Timeline 🔄 Live

First Seen2026-07-11 02:18:22 UTC
Last Seen2026-09-02 11:16:05 UTC
Profile Built2026-09-02 11:19:47 UTC
Data FreshnessLive
Signal Types26
Total Observations29
🔍 26 signal types · 29 observations collected
This report is generated from 26+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 189.28.69.85

Who owns the IP address 189.28.69.85?

189.28.69.85 is registered to admin-ipbroker. The address falls within the 189.28.64.0/20 network block. Registration is held at LACNIC.

Where is 189.28.69.85 located?

Geolocation data places 189.28.69.85 in New York, US-NY, United States. The local time zone is America/New_York. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 189.28.69.85 malicious or safe?

189.28.69.85 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.

What is the hostname for 189.28.69.85?

The reverse DNS (PTR) record for 189.28.69.85 is LPZ-189-28-68-00085.tigo.bo. This hostname is not forward-confirmed, so it should be treated as a weak signal.

🏘️ Related IP Addresses

Nearby addresses in 189.28.64.0/20

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.