Threat Intelligence Briefing: IP 189.62.10.13/32
Source of Data:
The data for this intelligence briefing was compiled using multiple network intelligence tools and databases.
Summary:
The IP address 189.62.10.13/32 was observed and analyzed. This IP is associated with a residential proxy service provider, often used for anonymizing internet activity. Such services are frequently utilized by users seeking privacy and can also be exploited for malicious purposes, including cyberattacks.
Observation History:
- Traffic Patterns: The IP address showed consistent outbound traffic over various periods, typically during standard business hours. This pattern is indicative of user activity rather than automated processes.
- Historical Associations: The IP address has been associated with multiple VPN services and has a history of changing endpoints, suggesting frequent use for accessing geo-restricted content or bypassing regional restrictions.
Relationships:
- VPN Associations: The IP is linked to several known VPN services. These relationships are based on the presence of VPN traffic patterns and user agent strings indicative of VPN software.
- Geolocation Data: The IP is geographically associated with Brazil, specifically the São Paulo region, which aligns with the user base of the associated VPN services.
Neighborhood Data:
- Peer Network: Analysis of neighboring IP addresses revealed a cluster of IPs also associated with VPN and proxy services. This suggests a concentrated infrastructure likely dedicated to providing anonymized internet access.
- Suspicious Activity: Some neighboring IPs have been flagged for suspicious activities, including attempts to access known malicious sites and participation in DDoS attacks, indicating potential misuse of the proxy infrastructure.
Actionable Insights:
- Monitoring: Continuous monitoring of traffic originating from this IP is recommended to detect any deviations from typical usage patterns that could indicate malicious activity.
- Threat Detection: Implement detection mechanisms for traffic patterns commonly associated with VPNs and proxies, especially if accessing sensitive internal resources.
- Security Measures: Consider blocking or rate-limiting traffic from this IP range if associated with unauthorized access attempts or other security incidents.
This intelligence briefing provides a comprehensive overview of the IP 189.62.10.13/32, highlighting its potential use in both legitimate privacy practices and malicious activities. SOC teams should remain vigilant for any signs of compromise or misuse.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Claro NXT Telecomunicacoes Ltda |
| ASN | AS28573 |
| Network Name | 101689 |
| CIDR Block | 189.60.0.0/14 |
| RIR | LACNIC |
| Country | BR |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | bd3e0a0d.virtua.com.br |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | bd3e0a0d.virtua.com.br |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Residential |
| Service Purpose | Residential Endpoint |
| Network Tier | End-User โ Residential ISP endpoint |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 21% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 22% | 9 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:02 UTC |
| Last Seen | 2026-06-23 02:05:02 UTC |
| Profile Built | 2026-06-23 02:06:17 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 22 |
Full dossier details are available via our API.