# IP Intelligence Briefing: 190.143.242.67/32
## Executive Summary
IP address 190.143.242.67 presents a moderate risk profile (score: 40) with no active malicious indicators. The IP is geolocated to Newark, NJ but resolves to a Nigerian domain, with DNSBL listings and failed geo-validation. No open services were detected; the host appears firewalled.
## Risk Assessment
- Overall Risk Score: 40 (Moderate Risk)
- Provider Score: 0 (No provider data available)
- Authority Score: 0
- Stability: No ownership changes detected; threat persistence days: 0
- Persistence Classification: Not persistently malicious
## Geolocation & Network Context
- Location: Newark, New Jersey, US (US-NJ)
- Region: America/New_York timezone
- Geolocation Confidence: Low (2 sources, consensus: false, geoPlausible: false)
- Control Plane: Origin ASN 28036, BGP prefix 190.143.242.0/24
- Route Stability: False (route changes observed)
- DNSSEC: Valid
- Traceroute: 30 hops, 16 timeouts, transit via Comcast
## DNS & Hostname Analysis
- PTR Record: host67-242-143-190.tigobusiness.com.ni
- Forward Resolution: Confirmed
- Hosted Domains: 0
- Email Authentication: SPF: false, DMARC: false
- DNSBL Listings: 2 out of 8 total lists
- Anomaly: Nigerian .ni TLD with US geolocation suggests infrastructure misconfiguration or foreign hosting
## Service Profile
- Open Ports: None detected
- Service Classification: Firewalled / No Services
- TLS Certificate: None
- HTTP Banner: None
- WAF Violations: 0
- Honeypot Hits: 0
## Threat Indicators
- Known Attacker: false
- Spam Source: false
- Tor Exit Node: false
- Proxy/VPN/CDN/Cloud: false
- Abuse Confidence Score: null
- Known Campaigns: None
- Blacklist Count: 0 (despite DNSBL presence)
- Threat Feeds: None
## Neighborhood Analysis (190.143.242.0/24)
- Subnet Abuse Density: 0 (Low)
- Total Siblings: 2
- Active Siblings: 2
- Threat Siblings: 0
- Neighbor Risk Scores:
- 190.143.242.148: Risk 0, Authority 50
- 190.143.242.182: Risk 25, Authority 60
## Historical Observations
- Total Observations: 15
- Most Recent: 2026-07-23
- Signal Types: Network role, ownership, HTTP errors (429), operator score, profile dimensions
- Threat Observation Count: 0
- Key Finding: Recent HTTP 429 responses observed, suggesting rate limiting or automated interaction
## Relationships
- DNS Associations: 4 entries, all pointing to host67-242-143-190.tigobusiness.com.ni
- No additional relationships: No organizations, certificates, or related IPs detected
## Recommended Actions
Current Risk Score: 40
Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 190.143.242.67 -j DROP
# nftables
nft add rule inet filter input ip saddr 190.143.242.67 drop
# nginx
deny 190.143.242.67;
# pfSense
190.143.242.67/32
# Cloudflare WAF
{"description":"Block 190.143
---
AWS WAF:
```json
{
"Addresses": ["190.143.242.67/32"],
"Description": "IPDebrief risk 40"
}
```
## Threat Intelligence Narrative
The target IP 190.143.242.67 exhibits moderate risk characteristics with no confirmed malicious activity. Key indicators include DNSBL listings (2 of 8 lists), failed geolocation validation (US location vs. .ni Nigerian domain), and route instability within the 190.143.242.0/24 subnet. The absence of open ports and services indicates the host is either actively firewalled or functioning as infrastructure rather than an endpoint.
Historical observation data shows 15 total signals collected as of July 2026, with HTTP 429 responses detected, suggesting rate-limiting behavior or automated probing attempts. The subnet contains 2 active neighbors with low-to-moderate risk scores, indicating limited lateral threat activity.
## SOC Analyst Guidance
Monitor for:
- Increased DNSBL listings
- New open ports or service banners
- Correlated IP activity from neighbors 190.143.242.148 or 190.143.242.182
- Changes in geolocation confidence
Action Thresholds:
- Risk Score > 50: Consider blocking
- Risk Score 40-50: Monitor with logging enabled
- Risk Score < 30: Allow with standard inspection
Recommendation: Implement the recommended firewall rules if traffic patterns warrant. The moderate risk score combined with geographic inconsistency suggests potential infrastructure misconfiguration or low-level abuse capability, but no active threats were detected in the observation window.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Telefonia Celular de Nicaragua SA. |
| ASN | AS28036 |
| Network Name | 190.143.240.0 - 190.143.255.255 |
| CIDR Block | 190.143.240.0/20 |
| RIR | LACNIC |
| Country | NI |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | host67-242-143-190.tigobusiness.com.ni |
| Forward Confirmed | Yes — FCrDNS verified |
| Forward Hostnames | host67-242-143-190.tigobusiness.com.ni |
🔐 DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 — Basic operator with some routing infrastructure |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS28036 |
| Network Prefix | 190.143.242.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-05 05:35:13 UTC |
| Last Seen | 2026-08-26 23:39:35 UTC |
| Profile Built | 2026-08-29 07:01:18 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 19 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 190.143.242.67
Who owns the IP address 190.143.242.67?
190.143.242.67 is registered to Telefonia Celular de Nicaragua SA.. The address falls within the 190.143.240.0/20 network block. Registration is held at LACNIC.
Where is 190.143.242.67 located?
Geolocation data places 190.143.242.67 in Newark, US-NJ, United States. The local time zone is America/New_York. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 190.143.242.67 malicious or safe?
190.143.242.67 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 190.143.242.67?
The reverse DNS (PTR) record for 190.143.242.67 is host67-242-143-190.tigobusiness.com.ni. This hostname is forward-confirmed, meaning it resolves back to the same address.