# IP Intelligence Briefing: 191.88.140.98/32
Date: 2026-07-31
Classification: LOW RISK
Analyst: IPDebrief Automated Intelligence System
---
## Executive Summary
IP address 191.88.140.98 is a low-risk residential mobile IP assigned to Colombia Móvil (ASN 13489) in Medellín, Colombia. The IP exhibits no active threat indicators and no known malicious associations. Monitoring suggests standard mobile network traffic patterns with no observed abuse activity.
---
## Network Ownership & Infrastructure
| Attribute | Value |
|---|---|
| **ASN** | 13489 |
| **Organization** | Colombia Móvil |
| **Network Block** | 191.88.0.0/13 |
| **RIR** | LACNIC |
| **Abuse Contact** | abuse.internet@tigo.com.co |
| **Geolocation** | Medellín, Antioquia, Colombia |
Network Role Classification: Mobile carrier IP (Movistar/LTE). The address is not associated with cloud hosting, CDN, VPN, proxy, or hosting services. The IP is firewalled with no open services detected.
---
## Risk Assessment
| Metric | Value | Assessment |
|---|---|---|
| **Overall Risk Score** | 25 | Low Risk |
| **Provider Score** | 0 | Neutral |
| **Authority Score** | 0 | Neutral |
| **Abuse Confidence** | Not reported | Low |
| **Blacklist Count** | 0 | Clean |
| **Known Campaigns** | None | None detected |
Threat Indicators: No indicators of malicious activity detected. IP is not identified as a Tor exit node, known attacker, or spam source. No threat feed matches.
---
## DNS & Service Analysis
| Metric | Value |
|---|---|
| **PTR Hostname** | Dinamic-BA-RES-191-88-140-98.tigoune.com.co |
| **Forward Resolution** | 1 confirmed hostname |
| **DNSSEC Valid** | Yes |
| **Open Ports** | None detected |
| **TLS Certificate** | Not detected |
| **HTTP Banner** | None |
| **Email Auth** | SPF: No, DMARC: No |
Observation: The dynamic hostname pattern (Dinamic-BA-RES-191-88-140-98.tigoune.com.co) is consistent with residential mobile IP address assignment practices.
---
## Neighborhood Analysis
| Metric | Value |
|---|---|
| **Subnet** | 191.88.140.98/24 |
| **Abuse Density** | 0 |
| **Neighbor Count** | 0 |
| **High Risk Neighbors** | 0 |
| **Medium Risk Neighbors** | 0 |
| **Low Risk Neighbors** | 0 |
Assessment: No adjacent sibling IPs identified. Subnet exhibits zero abuse density, indicating isolated clean assignment.
---
## Relationship Graph
| Relationship Type | Target | Count |
|---|---|---|
| Same Network | 191.88.0.0 - 191.95.255.255 | 3 entries |
| DNS Association | Dinamic-BA-RES-191-88-140-98.tigoune.com.co | 3 entries |
Assessment: Relationships confirm standard mobile network infrastructure with no suspicious lateral associations.
---
## Historical Signal Timeline
Observation Count: 12 signals recorded
Recent Activity (2026-07-31):
- 00:59:37 โ Geolocation signal: Medellín, Antioquia, Colombia (Confidence: 70%)
- 00:58:45 โ Operator score signal: Minimal (0.1304) (Confidence: 60%)
- 00:57:44 โ Ownership signal: Colombia Móvil, ASN 13489 (Confidence: 95%)
Temporal Analysis: Consistent Colombia-based geolocation signals. No significant risk escalation or ownership changes detected. Threat persistence: 0 days.
---
## Control Plane Analysis
| Metric | Value |
|---|---|
| **Origin ASN** | 13489 |
| **BGP Prefix** | 191.88.0.0/16 |
| **Route Stable** | No |
| **RPKI State** | Not evaluated |
| **DNSBL Listed** | 1 of 8 lists |
| **Route Changes (30d)** | 0 |
Assessment: Minimal route instability detected. Single DNSBL listing among 8 checked lists indicates no significant reputation impact.
---
## Recommended Actions
Current Risk Level: Low (Score: 25)
| Action Category | Recommendation | Priority |
|---|---|---|
| **Firewall** | No blocking recommended | N/A |
| **Monitoring** | Standard logging sufficient | Low |
| **Threat Intel** | No enrichment required | N/A |
| **ISP Contact** | No abuse reporting needed | N/A |
---
## Intelligence Conclusions
1. Threat Status: No malicious activity detected. IP operates within expected mobile carrier parameters.
2. Risk Context: The low risk score (25/100), combined with zero blacklist entries, zero open ports, and no threat feed matches, indicates this is a benign residential mobile IP.
3. Operational Recommendation: No defensive actions required. Standard traffic logging and monitoring protocols are sufficient.
4. Contextual Notes: The dynamic hostname pattern (Dinamic-BA-RES-191-88-140-98.tigoune.com.co) is a standard mobile carrier practice in Colombia. The absence of SPF/DMARC records is consistent with residential/mobile IP usage.
Final Assessment: This IP address represents normal mobile network infrastructure with no security concerns. No further intelligence collection or defensive measures are warranted at this time.
---
*Report generated by IPDebrief Intelligence Platform. All data sourced from automated IP reputation feeds and real-time network analysis.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Colombia Móvil |
| ASN | AS13489 |
| Network Name | 191.88.0.0 - 191.95.255.255 |
| CIDR Block | 191.88.0.0/13 |
| RIR | LACNIC |
| Country | CO |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | Dinamic-BA-RES-191-88-140-98.tigoune.com.co |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | Dinamic-BA-RES-191-88-140-98.tigoune.com.co |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 16% | 4 | 5 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-30 04:58:50 UTC |
| Last Seen | 2026-08-12 18:30:46 UTC |
| Profile Built | 2026-08-12 06:13:31 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 21 |
Full dossier details are available via our API.