# IP INTELLIGENCE BRIEFING: 190.89.137.4
## Executive Summary
Risk Score: 80/100 (HIGH RISK)
This IP address presents a high-risk threat profile requiring immediate attention. Located in Brazil under residential infrastructure classification, the IP demonstrates multiple blacklist listings and elevated neighborhood risk density.
---
## Network Profile
| Attribute | Value |
|---|---|
| **Organization** | T. R. TELECOMUNICACOES LTDA |
| **ASN** | AS270368 |
| **Network** | 190.89.136.0/23 |
| **Geolocation** | Brazil (BR), São Paulo, Votuporanga |
| **Classification** | Residential Endpoint |
| **CIDR Block** | 190.89.137.4/32 |
---
## Threat Assessment
Risk Indicators:
- DNSBL Status: Listed on 4 of 8 total blacklists
- Abuse Confidence: Multiple high-severity listings observed
- Neighborhood Risk: 40.62% abuse density in /24 subnet
- Subnet Context: 65 threat-siblings among 160 total IPs in neighborhood
Network Behavior:
- No active open ports detected
- No TLS certificates or web services
- No email authentication (SPF/DMARC absent)
- Residential infrastructure type
---
## Temporal Analysis
Observation History: 18 signals recorded
- Recent DNSBL listings observed (June 2026 timeframe)
- Consistent ASN and prefix confirmations
- Operator score: Minimal (0.13)
- No persistent malicious activity pattern detected
---
## Related Infrastructure
Subnet Analysis (190.89.137.0/24):
- Total Siblings: 160 IPs
- Active Siblings: 61
- Threat Siblings: 65
- Risk Distribution: 28 high-risk, 63 medium-risk, 8 low-risk
Network Relationships: All 21 detected relationships link to network 378879, indicating concentrated infrastructure usage.
---
## Recommended Actions
Immediate Response:
1. Block traffic from 190.89.137.4/32 at perimeter
2. Increase logging verbosity for all traffic from this IP
3. Review recent activity patterns and connection attempts
Firewall Implementation:
- iptables: `iptables -A INPUT -s 190.89.137.4 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 190.89.137.4 drop`
- nginx: `deny 190.89.137.4;`
- Cloudflare WAF: Block rule with expression `ip.src eq 190.89.137.4`
---
## Analyst Notes
The IP resides in a residential network segment with moderate-to-high abuse density. While no active exploitation indicators were detected during profiling, the combination of blacklist listings and neighborhood context suggests potential for opportunistic abuse. Recommend correlating with internal threat intelligence feeds before final disposition. Monitor for related IPs in the 190.89.137.0/24 subnet exhibiting similar patterns.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | T. R. TELECOMUNICACOES LTDA |
| ASN | AS270368 |
| Network Name | 378879 |
| CIDR Block | 190.89.136.0/23 |
| RIR | LACNIC |
| Country | BR |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Residential |
| Service Purpose | Residential Endpoint |
| Network Tier | End-User โ Residential ISP endpoint |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 3 |
| routing | 20% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 15% | 2 | 2 |
| reputation | 19% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 19% | 9 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-10 22:17:27 UTC |
| Last Seen | 2026-06-26 04:53:48 UTC |
| Profile Built | 2026-06-26 05:01:40 UTC |
| Data Freshness | Live |
| Signal Types | 15 |
| Total Observations | 18 |
Full dossier details are available via our API.