IPDebrief

191.53.18.15

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING

Target: 191.53.18.15/32

Date: 2026-06-23

Classification: High Risk

---

## EXECUTIVE SUMMARY

IP address 191.53.18.15 is classified as High Risk with a risk score of 70. The IP is associated with MASTER S/A (AS28202) in Divinópolis, Minas Gerais, Brazil. The address shows evidence of blacklist listings (8 DNSBL entries, 4 active listings with high severity) and operates within a subnet exhibiting 33.3% abuse density. The IP is currently firewalled with no active services.

---

## OWNERSHIP & REGISTRATION

---

## GEOLOCATION

---

## THREAT INDICATORS

---

## NETWORK STATUS

---

## CONTROL PLANE ANALYSIS

---

## OBSERVATION HISTORY

Total Observations: 23 signals

Recent Activity (2026-06-23):

Historical Trend: One threat observation recorded on 2026-06-17 with reputation score of 0 and 2 threat pulses associated. No evidence of persistent malicious behavior (threat persistence days: 0).

---

## NEIGHBORHOOD ANALYSIS

Subnet: 191.53.18.15/24

Abuse Density: 33.3% (profile) / 15% (neighbor analysis)

Total Siblings: 18 active IPs

Threat Siblings: 6

High-Risk Neighbors (Risk Score โ‰ฅ70):

IP AddressRisk ScoreAuthority Score
191.53.18.368050
191.53.18.398050
191.53.18.87050
191.53.18.1117050
191.53.18.1137050
191.53.18.1297050
191.53.18.1377050
191.53.18.1847050
191.53.18.2167050

Risk Distribution: 3 high, 14 medium, 3 low

---

## RELATIONSHIP GRAPH

Total Relationships: 35 entities

---

## RECOMMENDED ACTIONS

1. Block Traffic: Implement firewall rules to block inbound and outbound traffic from 191.53.18.15/32

2. Monitor Subnet: Apply enhanced monitoring to 191.53.18.0/24 subnet due to 33% abuse density and presence of multiple high-risk neighbors

3. DNSBL Verification: Review and block against 8 DNSBL lists where the IP is currently listed

4. Ingress Filtering: Consider RPF checks for traffic from AS28202

5. Log Correlation: Correlate with threat intelligence feeds for AS28202 and related network identifier 227148

---

## ASSESSMENT

The target IP demonstrates a moderate-high risk profile primarily driven by blacklist listings and subnet-level abuse patterns. While the IP itself shows no direct threat indicators (not a known attacker, spam source, or Tor exit node), its association with multiple high-risk neighbors and non-stable routing configuration warrants defensive blocking and continuous monitoring. The subnet's mixed classification suggests varied threat vectors requiring differentiated response policies.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ง๐Ÿ‡ท Brazil
RegionMinas Gerais
CityDivinópolis
Timezoneโ€”
Latitude-21.55
Longitude-45.43

๐Ÿข Ownership & Registration

OrganizationMASTER S/A
ASNAS28202
Network Name227148
CIDR Block191.53.0.0/16
RIRLACNIC
CountryBR
Abuse Contactโ€”

๐ŸŒ DNS Intelligence

PTR191-53-18-15.vga-wr.soumaster.com.br
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnames191-53-18-15.vga-wr.soumaster.com.br

๐Ÿ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown โ€” Insufficient routing data to classify
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
22%
24
routing
17%
11
services
15%
22
ownership
15%
22
reputation
21%
13
geolocation
21%
22
Overall19%1014
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-07 23:04:03 UTC
Last Seen2026-06-23 02:33:57 UTC
Profile Built2026-06-23 02:43:29 UTC
Data FreshnessLive
Signal Types21
Total Observations23
๐Ÿ” 21 signal types ยท 23 observations collected
This report is generated from 21+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.