# IP Intelligence Briefing: 190.128.201.18/32
## Executive Summary
The IP address 190.128.201.18 is a Telecel S.A. infrastructure address located in Asunción, Paraguay, with a moderate risk score of 65/100. The IP exhibits firewalled status with no active services and represents a regional ISP allocation. SOC teams should monitor for anomalous outbound connections from this address.
---
## Risk Profile
| Attribute | Value |
|---|---|
| Risk Score | 65/100 (Moderate Risk) |
| Reputation | Moderate Risk |
| Organization | Telecel S.A. (AS23201) |
| Country | Paraguay (PY) |
| City | Asunción |
| RIR | LACNIC |
| ASN | 23201 |
---
## Network Characteristics
- Infrastructure Type: Provider/ISP infrastructure
- Network Role: Firewalled / No Services Detected
- DNS PTR: static-18-201-128-190.telecel.com.py
- BGP Prefix: 190.128.128.0/17
- Route Stability: Not stable (route changes observed in 30-day window)
- Open Ports: None detected
- TLS/HTTP Services: None
---
## Threat Indicators
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Blacklist Count: 0
- Threat Feeds: None detected
- Campaign Correlation: No matches
- Malicious Activity Days: 0
---
## Subnet Analysis (190.128.201.0/24)
- Abuse Density: 1/256 (low)
- Classification: Mostly Clean
- Active Siblings: 1
- Threat Siblings: 1
- Inherited Risk: 2/100
---
## Observation History (Recent 25 Observations)
The IP has shown temporal signals including:
- 2026-06-23: ASN 23201 with prefix 190.128.192.0/18
- 2026-06-17: ASN 23201 with prefix 190.128.128.0/17
- DNSSEC Validation: Confirmed
- Operator Score: 0.1304 (Minimal)
---
## Related Entities (76 Relationships)
- Multiple "Same Network" relationships to 190.128.192.0 - 190.128.255.255 range
- No external hostname or certificate relationships detected
---
## Recommended Actions
Priority: High
1. Monitoring: Increase logging verbosity and review recent activity from this IP
2. Block Recommendation: Consider blocking if inbound connection attempts observed
Firewall Rules:
- iptables: `iptables -A INPUT -s 190.128.201.18 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 190.128.201.18 drop`
- nginx: `deny 190.128.201.18;`
- pfSense: `190.128.201.18/32`
---
## Assessment Notes
This IP represents legitimate ISP infrastructure from Paraguay. The elevated risk score (65) appears to be driven by route instability and the presence of one threat sibling in the subnet rather than confirmed malicious activity from this specific address. Recommend monitoring outbound connections from this IP to internal resources and correlating with internal traffic patterns.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Telecel S.A. |
| ASN | AS23201 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | LACNIC |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | static-18-201-128-190.telecel.com.py |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | static-18-201-128-190.telecel.com.py |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 21% | 1 | 3 |
| geolocation | 13% | 1 | 1 |
| Overall | 20% | 9 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:03 UTC |
| Last Seen | 2026-06-26 18:10:57 UTC |
| Profile Built | 2026-06-23 02:24:40 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 27 |
Full dossier details are available via our API.