IPDebrief

190.143.242.67

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 190.143.242.67/32

## Executive Summary

IP address 190.143.242.67 presents a moderate risk profile (score: 40) with no active malicious indicators. The IP is geolocated to Newark, NJ but resolves to a Nigerian domain, with DNSBL listings and failed geo-validation. No open services were detected; the host appears firewalled.

## Risk Assessment

## Geolocation & Network Context

## DNS & Hostname Analysis

## Service Profile

## Threat Indicators

## Neighborhood Analysis (190.143.242.0/24)

- 190.143.242.148: Risk 0, Authority 50

- 190.143.242.182: Risk 25, Authority 60

## Historical Observations

## Relationships

## Recommended Actions

Current Risk Score: 40

Firewall Rules:

```bash

# iptables

iptables -A INPUT -s 190.143.242.67 -j DROP

# nftables

nft add rule inet filter input ip saddr 190.143.242.67 drop

# nginx

deny 190.143.242.67;

# pfSense

190.143.242.67/32

# Cloudflare WAF

{"description":"Block 190.143

---

AWS WAF:

```json

{

"Addresses": ["190.143.242.67/32"],

"Description": "IPDebrief risk 40"

}

```

## Threat Intelligence Narrative

The target IP 190.143.242.67 exhibits moderate risk characteristics with no confirmed malicious activity. Key indicators include DNSBL listings (2 of 8 lists), failed geolocation validation (US location vs. .ni Nigerian domain), and route instability within the 190.143.242.0/24 subnet. The absence of open ports and services indicates the host is either actively firewalled or functioning as infrastructure rather than an endpoint.

Historical observation data shows 15 total signals collected as of July 2026, with HTTP 429 responses detected, suggesting rate-limiting behavior or automated probing attempts. The subnet contains 2 active neighbors with low-to-moderate risk scores, indicating limited lateral threat activity.

## SOC Analyst Guidance

Monitor for:

Action Thresholds:

Recommendation: Implement the recommended firewall rules if traffic patterns warrant. The moderate risk score combined with geographic inconsistency suggests potential infrastructure misconfiguration or low-level abuse capability, but no active threats were detected in the observation window.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇺🇸 United States
RegionUS-NJ
CityNewark
TimezoneAmerica/New_York
Latitude12.13
Longitude-86.25

🏢 Ownership & Registration

OrganizationTelefonia Celular de Nicaragua SA.
ASNAS28036
Network Name190.143.240.0 - 190.143.255.255
CIDR Block190.143.240.0/20
RIRLACNIC
CountryNI
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRhost67-242-143-190.tigobusiness.com.ni
Forward ConfirmedYes — FCrDNS verified
Forward Hostnameshost67-242-143-190.tigobusiness.com.ni

🔐 DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierTier 3 — Basic operator with some routing infrastructure
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Server—
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS28036
Network Prefix190.143.242.0/24
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
0%
00
reputation
0%
00
geolocation
25%
11
Overall16%44
Coverage: 4/6 dimensions · Data sufficiency: partial
Data CoherenceMostly Consistent (80%) — 1 contradiction(s)
AttributionModerate (55%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Geo sources disagree on country: NI, US

📅 Observation Timeline 🔄 Live

First Seen2026-07-05 05:35:13 UTC
Last Seen2026-08-26 23:39:35 UTC
Profile Built2026-08-29 07:01:18 UTC
Data FreshnessLive
Signal Types17
Total Observations19
🔍 17 signal types · 19 observations collected
This report is generated from 17+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 190.143.242.67

Who owns the IP address 190.143.242.67?

190.143.242.67 is registered to Telefonia Celular de Nicaragua SA.. The address falls within the 190.143.240.0/20 network block. Registration is held at LACNIC.

Where is 190.143.242.67 located?

Geolocation data places 190.143.242.67 in Newark, US-NJ, United States. The local time zone is America/New_York. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 190.143.242.67 malicious or safe?

190.143.242.67 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.

What is the hostname for 190.143.242.67?

The reverse DNS (PTR) record for 190.143.242.67 is host67-242-143-190.tigobusiness.com.ni. This hostname is forward-confirmed, meaning it resolves back to the same address.

🏘️ Related IP Addresses

Nearby addresses in 190.143.240.0/20

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.