# THREAT INTELLIGENCE BRIEFING
Target IP: 189.28.69.85/32
Date: 2026-07-26
Classification: LOW RISK / DEFENSIVE MONITORING
---
## EXECUTIVE SUMMARY
IP 189.28.69.85 is a low-risk infrastructure address belonging to Tigo (ASN 27882) in Bolivia. The IP demonstrates minimal threat characteristics with a risk score of 25. However, it is listed on one of eight DNS-based blacklists, warranting continued monitoring. No active malicious indicators, open services, or known campaign associations were detected.
---
## NETWORK CLASSIFICATION & OWNERSHIP
- Provider: Tigo (Bolivian telecommunications provider)
- ASN: 27882
- Network: 189.28.69.0/24
- Geolocation: Santa Cruz de la Sierra, Bolivia
- PTR Record: LPZ-189-28-68-00085.tigo.bo
- Service Status: Firewalled / No Active Services (Open Ports: None)
---
## THREAT INDICATORS
| Indicator | Status |
|---|---|
| Risk Score | 25 (Low Risk) |
| DNSBL Listings | 1 of 8 (High Severity) |
| Tor Exit Node | No |
| Known Attacker | No |
| Spam Source | No |
| Campaign Association | None Detected |
Observation: The IP was rate-limited (HTTP 429) during recent observation, suggesting potential automated access attempts. One DNS blacklist listing with "high" severity was recorded during the 2026-07-26 observation window.
---
## NEIGHBORHOOD ANALYSIS
Subnet: 189.28.69.0/24
Abuse Density: 0.25 (Low/Moderate)
Classification: Mostly Clean
Sibling IP Assessment:
- 189.28.69.219: Risk Score 25
- 189.28.69.220: Risk Score 0 (Clean)
- 189.28.69.227: Risk Score 25
Assessment: The subnet maintains a stable, low-abuse profile with only one threat-sibling IP. The overall neighborhood risk is not elevated.
---
## OBSERVATION HISTORY
- Total Observations: 17 signals
- Recent Activity: 2026-07-26 (17 observations in single day)
- Threat Persistence: 0 days (Not persistently malicious)
- Ownership Changes: 0
---
## SECURITY RECOMMENDATIONS
Action Priority: LOW
1. Monitoring: Maintain passive monitoring on this IP. The single DNSBL listing warrants awareness but does not indicate immediate threat.
2. Allow Rule: No blocking required. Traffic may originate from legitimate Tigo infrastructure.
3. Rate Limiting: The HTTP 429 response indicates the source may attempt automated access. Consider applying standard rate-limiting policies if traffic originates from this range.
4. Block Consideration: Only recommended if the specific DNSBL listing is confirmed relevant to organizational security posture.
---
Analyst Notes: This IP represents legitimate telecommunications infrastructure with minimal threat characteristics. The blacklist listing and rate-limit response are typical of defensive infrastructure responses rather than active malicious behavior. No immediate containment actions required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | admin-ipbroker |
| ASN | AS27882 |
| Network Name | BO-TIGO-202304 |
| CIDR Block | 189.28.64.0/20 |
| RIR | LACNIC |
| Country | BO |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | LPZ-189-28-68-00085.tigo.bo |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | LPZ-189-28-68-00085.tigo.bo |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS27882 |
| Network Prefix | 189.28.69.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 0% | 0 | 0 |
| Overall | 8% | 2 | 2 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-11 02:18:22 UTC |
| Last Seen | 2026-09-02 11:16:05 UTC |
| Profile Built | 2026-09-02 11:19:47 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 29 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 189.28.69.85
Who owns the IP address 189.28.69.85?
189.28.69.85 is registered to admin-ipbroker. The address falls within the 189.28.64.0/20 network block. Registration is held at LACNIC.
Where is 189.28.69.85 located?
Geolocation data places 189.28.69.85 in New York, US-NY, United States. The local time zone is America/New_York. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 189.28.69.85 malicious or safe?
189.28.69.85 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 189.28.69.85?
The reverse DNS (PTR) record for 189.28.69.85 is LPZ-189-28-68-00085.tigo.bo. This hostname is not forward-confirmed, so it should be treated as a weak signal.