IP Intelligence Briefing: 189.28.90.110
Date: 2026-06-13
---
**1. Core Profile**
- Risk Score: Low (0/100)
- Threat Indicators: No active malware, phishing, or exploit campaigns detected.
- Geolocation:
- Reported Location: New York, NY, US (via IP geolocation).
- Actual Registration: Bolivia (BO) under TIGO ISP (LACNIC RIR).
- Discrepancy: Geolocation mismatch with network registration (Bolivia vs. US). Potential spoofing or misconfigured routing.
- Ownership:
- Organization: `admin-ipbroker` (TIGO.net.bo).
- Abuse Contact: `ipabuse@tigo.net.bo`.
- ASN: Unassigned.
---
**2. Threat Observations**
- Historical Activity (14 records):
- Low-Score Threats:
- Listed in 8 threat feeds (e.g., DNSBLs, abuse reports).
- High-severity listing in one feed (confirmed via signal_type_id 2344).
- Geolocation Conflicts:
- IP registered to Bolivia but geolocated in the US.
- Potential misrouting or spoofing.
- No Active Malicious Behavior:
- No open ports, TLS certs, or server banners detected.
---
**3. Network Relationships**
- No Direct Relationships:
- No linked domains, certificates, or subnets in the IPβs relationship graph.
- Recommendation: Investigate TIGOβs network for potential misconfigurations or compromised subnets.
---
**4. Subnet Analysis**
- Subnet: `189.28.90.110/24`
- Neighbor Risk:
- Total Siblings: 2 IPs.
- High-Risk Neighbor: `189.28.90.212` (riskScore: 50).
- Abuse Density: 0% (clean subnet).
- Action Required: Monitor `189.28.90.212` for suspicious activity, as it may be a vector for lateral movement.
---
**5. Recommendations**
1. Verify Geolocation: Confirm if the IP is legitimately hosted in the US or if there is spoofing.
2. Engage TIGO: Contact `ipabuse@tigo.net.bo` to resolve the Bolivia-US discrepancy and investigate abuse reports.
3. Monitor Neighbors: Watch `189.28.90.212` for signs of compromise or malicious traffic.
4. Threat Feed Scrutiny: Validate the high-severity listing in threat feeds to determine if itβs a false positive.
---
Conclusion:
The IP appears low-risk but exhibits critical inconsistencies (geolocation vs. registration) and historical threat feed listings. While no immediate action is required, the anomalies warrant further investigation to prevent potential misrouting or network compromise.
Tool Sources: IPDebrief (profile, history, neighbors).
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | admin-ipbroker |
| ASN | AS27882 |
| Network Name | BO-TIGO-202304-02 |
| CIDR Block | 189.28.80.0/20 |
| RIR | LACNIC |
| Country | BO |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | LPZ-189-28-90-00110.tigo.bo |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | LPZ-189-28-90-00110.tigo.bo |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 17% | 1 | 1 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 17% | 1 | 1 |
| geolocation | 0% | 0 | 0 |
| Overall | 5% | 2 | 2 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-06-06 19:45:49 UTC |
| Last Seen | 2026-06-13 15:35:39 UTC |
| Profile Built | 2026-06-13 15:49:13 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 20 |
Full dossier details are available via our API.