# Threat Intelligence Briefing: 189.28.91.124
Classification: LOW RISK
Date: 2026-07-26
Analyst: IPDebrief Intelligence Team
## Executive Summary
IP address 189.28.91.124 presents as a low-risk infrastructure asset with no active threat indicators. The IP is associated with Tigo Bolivia (Admin-IPBroker) and is currently firewalled with no active services. While the broader /24 subnet shows moderate abuse density, this specific address shows no malicious activity.
## Technical Profile
| Attribute | Value |
|---|---|
| **IP Address** | 189.28.91.124/32 |
| **Risk Score** | 0 |
| **ASN** | 27882 |
| **Organization** | admin-ipbroker |
| **Network** | BO-TIGO-202304-02 |
| **Country** | Bolivia (BO) |
| **City** | La Paz |
| **RIR** | LACNIC |
| **CIDR Block** | 189.28.80.0/20 |
## Threat Assessment
Current Risk Status: No active threats detected
- No threat indicators in feeds
- Not listed on any blacklists (0/8 DNSBL)
- Not identified as Tor exit node, proxy, or known attacker
- No spam source reputation
Service Analysis:
- No open ports detected
- No TLS certificates or HTTP services running
- Classification: Firewalled / No Services
## Network Context
Subnet Analysis (189.28.91.0/24):
- Abuse Density: 0.5 (moderate)
- Classification: Mostly clean
- Total sibling IPs: 2
- Active sibling IPs: 1
- Threat sibling IPs: 1
- Notable neighbor: 189.28.91.162 (Risk Score: 25)
Control Plane:
- BGP Prefix: 189.28.91.0/24
- Route Stability: False
- DNSSEC: Valid
- Route Changes (30d): 0
## DNS & Hostname Associations
- PTR Record: LPZ-189-28-91-00124.tigo.bo
- Forward Resolution: tigo.bo
- Hosted Domain Count: 0
- Email Authentication: None (no SPF/DMARC configured)
## Historical Signals
Observation Count: 17 signals recorded
- Most recent: 2026-07-26 16:38 UTC
- Ownership Changes: 0
- Threat Persistence Days: 0
- Persistent Malicious Activity: False
## Intelligence Observations
1. Infrastructure Asset: IP appears to be part of a residential/corporate ISP allocation (Tigo Bolivia) with no hosting or proxy services configured.
2. Minimal Footprint: No reverse DNS issues, no open services, no historical abuse patterns.
3. Subnet Context: The /24 neighborhood contains one identified threat IP (189.28.91.162). Analysts should monitor this address for potential lateral activity.
4. Route Instability: Route is flagged as unstable, which may warrant monitoring for future infrastructure changes.
## Recommended Actions
Immediate: No blocking or firewall rules recommended. Risk score is zero with no active threat indicators.
Monitoring: Add to watchlist for subnet-level intelligence. Monitor 189.28.91.162 for continued malicious activity.
Long-term: No action required. IP maintains low-risk profile.
---
*Report generated by IPDebrief Intelligence Platform. This briefing is based on collected intelligence signals and should be correlated with additional threat data before operational decisions.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | admin-ipbroker |
| ASN | AS27882 |
| Network Name | BO-TIGO-202304-02 |
| CIDR Block | 189.28.80.0/20 |
| RIR | LACNIC |
| Country | BO |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | LPZ-189-28-91-00124.tigo.bo |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | LPZ-189-28-91-00124.tigo.bo |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS27882 |
| Network Prefix | 189.28.91.0/24 |
| Route mapping | Found |
| Certificates in transparency logs | 0 certificates |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 17% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 17% | 2 | 3 |
| reputation | 14% | 1 | 3 |
| geolocation | 12% | 2 | 2 |
| Overall | 13% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-11 02:18:22 UTC |
| Last Seen | 2026-09-01 01:49:42 UTC |
| Profile Built | 2026-09-01 01:56:09 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 26 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 189.28.91.124
Who owns the IP address 189.28.91.124?
189.28.91.124 is registered to admin-ipbroker. The address falls within the 189.28.80.0/20 network block. Registration is held at LACNIC.
Where is 189.28.91.124 located?
Geolocation data places 189.28.91.124 in La Paz, La Paz Department, BO. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 189.28.91.124 malicious or safe?
189.28.91.124 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 189.28.91.124?
The reverse DNS (PTR) record for 189.28.91.124 is LPZ-189-28-91-00124.tigo.bo. This hostname is not forward-confirmed, so it should be treated as a weak signal.