IPDebrief

190.89.137.211

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

IP Intelligence Briefing: 190.89.137.211

*Generated using IPDebrief Threat Intelligence*

---

**1. Core Profile**

- ISP: T. R. Telecomunicações Ltda (AS270368)

- Country: Brazil (BR)

- Region: São Paulo (SP)

- City: Votuporanga

- Plausibility: Low (RTT inconsistencies for distance)

- Coordinates: Latitude -14.24, Longitude -51.93 (2500km accuracy)

- Open ports: 80 (HTTP), 443 (HTTPS)

- No TLS certificate detected

---

**2. Threat & Behavior**

- No malware, spam, or attacker campaigns detected.

- No DNSBL listings or known malicious activity.

- Scanned on 2026-06-02 (ports 80/443 open, lighttpd banner).

- Residential classification (2026-06-17).

- Geo validation anomalies (RTT vs. distance).

---

**3. Network Relationships**

- Total: 100 IPs in /24 subnet.

- Abuse Density: 17% (17 high-risk, 77 medium-risk, 6 low-risk).

- High-Risk Neighbors: 17 (e.g., IPs with similar risk scores).

---

**4. Actionable Insights**

- Monitor for unexpected traffic spikes or port changes.

- Validate geolocation anomalies (RTT discrepancies).

- Consider blocking high-risk neighbors (e.g., IPs with 55+ risk scores) to mitigate subnet-level threats.

- Residential IPs are often targets for credential stuffing or DDoS.

- No direct malicious activity, but subnet abuse density suggests indirect risk.

---

Conclusion: 190.89.137.211 is a residential web server with no direct threat indicators, but its subnet contains notable risk. Prioritize monitoring for behavioral changes and consider subnet-level mitigation strategies.

*Generated by IPDebrief Threat Intelligence*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ง๐Ÿ‡ท Brazil
RegionSP
CityVotuporanga
Timezoneโ€”
Latitude-20.48
Longitude-50.01

๐Ÿข Ownership & Registration

OrganizationT. R. TELECOMUNICACOES LTDA
ASNAS270368
Network Name378879
CIDR Block190.89.136.0/23
RIRLACNIC
CountryBR
Abuse Contactโ€”

๐ŸŒ DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)

๐Ÿ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAAPresent

โ˜๏ธ Network Classification

InfrastructureResidential
Service PurposeWeb Server
Network TierEnd-User โ€” Residential ISP endpoint
Residential

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
443httpstcpโ€”
Closed Ports22, 25, 3389, 8080, 8443 (2 open / 7 scanned)
Serverlighttpd/1.4.39
HTTP Titleโ€”
โš  Unusual for residential โ€” open services on a home connection may indicate self-hosting, compromise, or misconfigured networking equipment.

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
45%
25
routing
21%
12
services
30%
24
ownership
15%
22
reputation
23%
13
geolocation
30%
23
Overall27%1019
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) โ€” 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Claimed geolocation contradicts RTT physics measurement

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-07 23:04:03 UTC
Last Seen2026-06-23 02:20:45 UTC
Profile Built2026-06-23 02:37:52 UTC
Data FreshnessLive
Signal Types22
Total Observations29
๐Ÿ” 22 signal types ยท 29 observations collected
This report is generated from 22+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.