# IPDEBRIEF INTELLIGENCE BRIEFING
Target IP: 191.123.73.192/32
Date: 2026-07-28
Classification: Moderate Risk Assessment
---
## EXECUTIVE SUMMARY
IP 191.123.73.192 is a Brazilian residential IP address assigned to TIM S/A (ASN 26615) with a moderate risk classification. The address demonstrates no active malicious behavior but is flagged on two DNSBL lists, warranting continued monitoring.
---
## OWNERSHIP & GEOLOCATION
| Attribute | Value |
|---|---|
| **Organization** | TIM S/A |
| **Network** | 191.120.0.0/14 (NETNAME: 224828) |
| **ASN** | 26615 |
| **Country** | Brazil (BR) |
| **Region/City** | Goiás, Goiânia |
| **CIDR Block** | 191.123.73.192/24 |
---
## THREAT ASSESSMENT
Current Risk Score: 50 (Moderate)
Abuse Confidence: Not detected
Known Campaigns: None
Threat Feeds: Empty
Positive Indicators
- No open ports detected (firewalled/no services)
- No Tor exit node activity
- No known attacker reputation
- No spam source classification
- Zero threat persistence days observed
Concerning Indicators
- Listed on 2 of 8 DNSBL checks (dnsblListedCount: 2)
- Operator score: 0.1304 (Minimal)
---
## NETWORK CHARACTERISTICS
- Infrastructure Type: Residential (not cloud/CDN/VPN/proxy)
- Connection Type: Not specified
- BGP Origin: 191.123.64.0/18
- Route Stability: False
- RPKI State: Not detected
- Route Changes (30d): 0
---
## OBSERVATION HISTORY
Total Observations: 15
Latest Observation: 2026-07-28 13:01:20 UTC
Historical Trends
- Geolocation: Consistent Brazil/Goiânia region attribution with coordinate variance across sources
- Subnet Classification: "Clean" (0 abuse density, 0 threat siblings)
- Threat Signals: 0 total incidents recorded
- Behavioral: No honeypot hits, enumeration strikes, or WAF violations detected
---
## RELATIONSHIP ANALYSIS
Connected Entities: 3 relationships detected
- All relationships point to network identifier 224828
- No certificate, hostname, or organizational relationships beyond network assignment
---
## NEIGHBORHOOD ANALYSIS
Subnet: 191.123.73.192/24
Abuse Density: 0
Risk Distribution: 0 high / 0 medium / 0 low
Active Siblings: 0
Threat Siblings: 0
*Note: No neighboring IPs returned in /24 analysis.*
---
## RECOMMENDED ACTIONS
Based on the moderate risk classification and DNSBL listings:
1. Monitor DNSBL status changes for this IP
2. Observe for emergence of open ports or service activity
3. Review traffic patterns for any anomalous behavior
4. Correlate with other TIM S/A network traffic if incident response is triggered
---
## ANALYST NOTES
The IP presents as a low-to-moderate risk residential address with no current active threat indicators. The moderate risk score (50) appears driven primarily by DNSBL listings rather than observed malicious behavior. No immediate blocking recommended; continue standard monitoring protocols.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | TIM S/A |
| ASN | AS26615 |
| Network Name | 224828 |
| CIDR Block | 191.120.0.0/14 |
| RIR | LACNIC |
| Country | BR |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS26615 |
| Network Prefix | 191.123.64.0/18 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 12% | 2 | 2 |
| reputation | 20% | 1 | 3 |
| geolocation | 12% | 2 | 2 |
| Overall | 15% | 10 | 14 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-17 23:21:54 UTC |
| Last Seen | 2026-09-05 19:40:10 UTC |
| Profile Built | 2026-09-05 19:53:29 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 25 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 191.123.73.192
Who owns the IP address 191.123.73.192?
191.123.73.192 is registered to TIM S/A. The address falls within the 191.120.0.0/14 network block. Registration is held at LACNIC.
Where is 191.123.73.192 located?
Geolocation data places 191.123.73.192 in Goiânia, Goiás, Brazil. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 191.123.73.192 malicious or safe?
191.123.73.192 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.