# IPDEBRIEF INTELLIGENCE BRIEFING
Target: 201.55.142.10/32
Date: 2026-07-30
Classification: HIGH RISK (Score: 80/100)
---
## EXECUTIVE SUMMARY
IP address 201.55.142.10 is assigned to ISUPER TELECOMUNICACOES INFO LTDA (ASN: 28620) in Maringá, Paraná, Brazil. The IP presents an elevated threat profile with a risk score of 80/100. While no active threat indicators were detected, the IP is listed on 4 DNSBLs and exhibits geolocation anomalies. The network segment shows minimal abuse density (0), with only one medium-risk neighbor identified.
---
## RISK ASSESSMENT
| Metric | Value | Status |
|---|---|---|
| Risk Score | 80/100 | High Risk |
| Provider Score | 0 | N/A |
| Authority Score | 0 | N/A |
| DNSBL Listings | 4 | Listed |
| Operator Score | 0.1304 | Minimal |
| Threat Persistence | 0 days | None |
---
## NETWORK ATTRIBUTES
- Organization: ISUPER TELECOMUNICACOES INFO LTDA
- ASN: 28620
- CIDR Block: 201.55.128.0/19
- Registered RIR: LACNIC
- Network Role: Firewalled / No Services Detected
- Infrastructure Type: Not Cloud, CDN, VPN, Proxy, or Tor
---
## GEOLOCATION ANALYSIS
Reported Location: Maringá, Paraná, Brazil
Coordinates: Latitude -14.24, Longitude -51.93
Accuracy Radius: 2500 km
โ ๏ธ GEOLOCATION ANOMALY DETECTED:
RTT measurement of 143.0ms violates the minimum possible RTT of 203.1ms for the reported 10,154 km distance. This discrepancy indicates geolocation data is unreliable. GeoPlausible validation returned false.
---
## THREAT INTELLIGENCE
Threat Indicators: None detected
Known Campaigns: None associated
Tor Exit Node: No
Known Attacker: No
Spam Source: No
Control Plane:
- Route Stability: Unstable
- Route Changes (30d): 0
- RPKI State: Not available
- DNSSEC Valid: Yes
DNSBL Status: Listed on 4 of 8 total threat feeds (abuseConfidenceScore unavailable)
---
## NEIGHBORHOOD ANALYSIS (/24: 201.55.142.0/24)
| IP Address | Risk Score | Authority Score |
|---|---|---|
| 201.55.142.10 | 80 | - |
| 201.55.142.205 | 55 | 50 |
| 201.55.142.60 | 15 | 50 |
| 201.55.142.157 | 0 | 60 |
| 201.55.142.244 | 0 | 50 |
Subnet Statistics:
- Total Siblings: 5
- Active Siblings: 0
- Threat Siblings: 0
- Abuse Density: 0
- Classification: Not inherited
---
## OBSERVATION HISTORY
12 observations recorded, most recent: 2026-07-30 21:21:08 UTC. No persistent malicious activity detected. Multiple signal types observed including geolocation inference, ASN lookup, and network role classification.
---
## RECOMMENDED ACTIONS
IMMEDIATE: Monitor with increased logging verbosity (Critical Severity)
Elevated risk score (80/100) requires enhanced monitoring.
Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 201.55.142.10 -j DROP
# nftables
nft add rule inet filter input ip saddr 201.55.142.10 drop
# nginx
deny 201.55.142.10;
# pfSense
201.55.142.10/32
# Cloudflare WAF
{"description":"Block 201.55.142.10 โ IPDebrief risk score 80","action":"block","filter":{"expression":"ip.src eq 201.55.142.10"}}
# AWS WAF
{"Addresses":["201.55.142.10/32"],"Description":"IPDebrief risk 80"}
```
---
## ANALYST NOTES
1. DNSBL Listings: Four DNSBL entries suggest historical abuse patterns. Investigate source of listings.
2. Geolocation Discrepancy: RTT violation indicates IP may not be physically located in Brazil. Consider this when assessing threat origin.
3. No Active Services: IP appears firewalled with no open ports or TLS certificates. May indicate passive monitoring or dormant infrastructure.
4. Neighbor 201.55.142.205: Medium-risk score (55) warrants investigation as potential correlated infrastructure.
---
Status: Monitor Recommended
Priority: Critical
Confidence: High (based on risk score and DNSBL presence)
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | ISUPER TELECOMUNICACOES INFO LTDA |
| ASN | AS28620 |
| Network Name | 557785 |
| CIDR Block | 201.55.128.0/19 |
| RIR | LACNIC |
| Country | BR |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-29 10:34:00 UTC |
| Last Seen | 2026-07-31 07:31:30 UTC |
| Profile Built | 2026-07-30 21:28:27 UTC |
| Data Freshness | Live |
| Signal Types | 15 |
| Total Observations | 15 |
Full dossier details are available via our API.