# IP Intelligence Briefing: 190.12.83.134
## Executive Summary
IP 190.12.83.134 presents as a high-risk web server (Risk Score: 80) operating within a Peruvian ASN but geolocated to Taiwan. The IP exhibits mixed geolocation signals and maintains presence on multiple DNS blacklists. No active threat indicators or known campaigns were identified, but the IP warrants monitoring due to its risk profile and control plane instability.
---
## Technical Profile
Ownership & Network Context
- ASN: 27843 (RENA WARE DEL PERU)
- Network Block: 190.12.83.128/29
- Organization: RENA WARE DEL PERU
- RIR: LACNIC
- Classification: Web Server / Infrastructure
Geolocation Discrepancy
- Primary Location: Taipei, Taiwan (TW)
- ASN Registration: Peru
- Multiple geo sources indicate conflicting positioning with consensus flag enabled
- Geoplausible: False (validation concerns)
Service Fingerprint
- Open Ports: 80/TCP (HTTP), 443/TCP (HTTPS), 22/TCP (SSH)
- Web Server: Apache/2.4.17 (Unix)
- Backend: PHP/5.5.30 (legacy version)
- SSL Certificate: FortiWAN, O=Fortinet, S=Taipei, C=TW
---
## Threat Assessment
Risk Indicators
- Risk Score: 80 (High Risk)
- DNSBL Listings: 5 of 8 total lists
- Operator Score: 0.1304 (Minimal)
- Route Stability: False (instability detected)
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
Historical Observations
- Total Signals: 18 observations
- Recent Activity: 2026-07-27
- Threat Persistence: None detected
- One observation flagged ASN 27843 with `has_threats: true` and 9 pulses in AlienVault OTX
Control Plane Analysis
- BGP Prefix: 190.12.82.0/23
- Route Changes (30d): 0
- RPKI State: Not evaluated
- DNSSEC Valid: True
---
## Neighborhood Analysis
- Subnet: 190.12.83.134/24
- Abuse Density: 0 (clean classification)
- Active Siblings: 0
- Threat Siblings: 0
- Inherited Risk: 0
The immediate /24 subnet shows no abuse density, but the /29 block contains only this single IP.
---
## Relationships
- Same Network: 190.12.83.128 - 190.12.83.135 (internal network block)
- No external entity relationships (organizations, hostnames, certificates)
---
## Security Recommendations
Immediate Actions
1. Block SSH (port 22) from untrusted sources if not required for legitimate access
2. Monitor for abuse - DNSBL presence indicates prior reputation issues
3. Validate SSL certificate chain and verify Fortinet certificate authenticity
4. Review Apache/PHP version - Apache 2.4.17 and PHP 5.5.30 are significantly outdated
Firewall Rules
```bash
# Block SSH from non-admin networks
iptables -A INPUT -p tcp --dport 22 -j DROP
# Rate limit HTTP/HTTPS traffic
iptables -A INPUT -p tcp --dport 80,443 -m limit --limit 10/minute -j ACCEPT
```
Threat Intelligence Notes
- Geographic mismatch between ASN registration (Peru) and geolocation (Taiwan) warrants investigation
- Legacy PHP 5.5.30 is vulnerable to multiple CVEs (CVE-2019-11043, CVE-2020-5081)
- DNSBL listings suggest prior spam or abuse activity
- Route instability may indicate infrastructure issues or hijacking attempts
Monitoring Priorities
- Track for new DNSBL additions
- Monitor for port scanning activity
- Observe for changes in geolocation signals
- Alert on any threat indicator emergence
---
*Report generated: Current timestamp*
*Intel Source: IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | RENA WARE DEL PERU |
| ASN | AS27843 |
| Network Name | 190.12.83.128 - 190.12.83.135 |
| CIDR Block | 190.12.83.128/29 |
| RIR | LACNIC |
| Country | PE |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 0% (None) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 443 | https | tcp | — |
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
CN=FortiWAN, O=Fortinet, S=Taipei, C=TW was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.| SANs | None |
| Valid From | 2014-12-19T08:53:47+00:00 |
| Valid Until | 2024-12-16T08:53:47+00:00 (expired) |
| TLS Protocol | Tls12 |
| Cipher Suite | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 3650 days |
🛡️ Public Network Snapshot
| Origin ASN | AS27843 |
| Network Prefix | 190.12.82.0/23 |
| Route mapping | Found |
| HSTS | Not detected |
| CSP | Not detected |
| HTTP/2 | Not detected |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 23% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 20% | 2 | 3 |
| ownership | 17% | 2 | 3 |
| reputation | 11% | 1 | 2 |
| geolocation | 15% | 2 | 2 |
| Overall | 16% | 10 | 14 |
| Data Coherence | Mixed Signals (60%) — 2 contradiction(s) |
| Attribution | Very Low (20%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
⚠ Geo sources disagree on country: PE, TW
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-15 10:08:51 UTC |
| Last Seen | 2026-09-29 20:35:56 UTC |
| Profile Built | 2026-09-26 02:31:16 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 24 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 190.12.83.134
Who owns the IP address 190.12.83.134?
190.12.83.134 is registered to RENA WARE DEL PERU. The address falls within the 190.12.83.128/29 network block. Registration is held at LACNIC.
Where is 190.12.83.134 located?
Geolocation data places 190.12.83.134 in Lima, Taipei, Taiwan. The local time zone is Asia/Taipei. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 190.12.83.134 malicious or safe?
190.12.83.134 currently carries a high risk assessment, meaning indicators associated with malicious or abusive activity have been observed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 190.12.83.134?
Responsive ports observed on 190.12.83.134 include 80, 443, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.