# IP Intelligence Briefing: 190.89.137.148/32
## Executive Summary
IP 190.89.137.148 is a residential endpoint located in Votuporanga, São Paulo, Brazil, operating under T. R. TELECOMUNICACOES LTDA (ASN 270368). The IP carries a moderate risk score of 55/100 with no active threat indicators or blacklist listings. The subnet exhibits mixed-classified activity with 28% abuse density.
## Network & Ownership Profile
- Organization: T. R. TELECOMUNICACOES LTDA
- ASN: 270368 (AS270368)
- Network Block: 190.89.136.0/23 (LACNIC registry)
- CIDR: 190.89.137.148/32
- Registration: 2020-02-17
- Geolocation: Brazil (BR), São Paulo state, Votuporanga
## Threat Assessment
- Risk Score: 55/100 (Moderate Risk)
- Threat Indicators: None detected
- Blacklist Status: Clean (0 entries)
- Known Campaigns: None
- Service Type: Residential Endpoint
- Infrastructure Flags: Not cloud, CDN, VPN, proxy, Tor, or hosting
- DNSBL Listings: 3 of 8 total lists (dnsblListedCount: 3)
## Neighborhood Analysis
The /24 subnet (190.89.137.0/24) contains 160 total sibling IPs with the following distribution:
- High Risk: 28 IPs (17.5%)
- Medium Risk: 63 IPs (39.4%)
- Low Risk: 9 IPs (5.6%)
- Abuse Density: 0.28 (28%)
- Active Siblings: 64 IPs
- Threat Siblings: 69 IPs
This indicates elevated but not anomalous abuse activity within the subnet.
## Historical Observation
Twelve signals observed from June 2026. Key observations include:
- 2026-06-26: Minimal threat classification, residential endpoint confirmed
- 2026-06-16: Residential infrastructure classification maintained
- 2026-06-06: ASN routing confirmed (AS270368), subnet abuse density data captured
No significant escalation or de-escalation trends observed. The IP has maintained consistent residential classification without persistent malicious activity indicators.
## Network Control Plane
- BGP Prefix: 190.89.137.0/24
- Route Stability: Unstable (isRouteStable: false)
- Route Changes (30d): 0
- RPKI State: Not validated
- DNSSEC: Valid
- Origin ASN: 270368
## Recommended Actions
Immediate Actions:
1. Logging: Increase verbosity and review recent traffic activity from this IP
2. Blocking Decision: Monitor initially; consider blocking if additional threat signals emerge
Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 190.89.137.148 -j DROP
# nftables
nft add rule inet filter input ip saddr 190.89.137.148 drop
# nginx
deny 190.89.137.148;
# pfSense
190.89.137.148/32
# Cloudflare WAF
{"description":"Block 190.89.137.148 β IPDebrief risk score 55","action":"block","filter":{"expression":"ip.src eq 190.89.137.148"}}
# AWS WAF
{"Addresses":["190.89.137.148/32"],"Description":"IPDebrief risk 55"}
```
## Analyst Notes
This IP represents a residential endpoint in a moderately abused subnet. The risk score of 55 warrants monitoring but does not indicate active malicious behavior. The residential classification and lack of threat indicators suggest this may be legitimate residential traffic. Consider the subnet context when evaluating blocking decisionsβthe 28% abuse density indicates broader regional activity patterns.
Classification: Moderate Risk / Monitor
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | T. R. TELECOMUNICACOES LTDA |
| ASN | AS270368 |
| Network Name | 378879 |
| CIDR Block | 190.89.136.0/23 |
| RIR | LACNIC |
| Country | BR |
| Abuse Contact | β |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Residential |
| Service Purpose | Residential Endpoint |
| Network Tier | End-User β Residential ISP endpoint |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 19% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 19% | 2 | 2 |
| reputation | 13% | 1 | 2 |
| geolocation | 19% | 2 | 2 |
| Overall | 15% | 9 | 10 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-11 21:10:41 UTC |
| Last Seen | 2026-06-26 12:17:16 UTC |
| Profile Built | 2026-06-26 12:33:21 UTC |
| Data Freshness | Live |
| Signal Types | 14 |
| Total Observations | 21 |
Full dossier details are available via our API.