V.tal IP Ranges
V.tal is the neutral fibre network carved out of Oi, and AS7738 is the number Oi's Telemar arm has held since March 1998. The registro.br record served for LACNIC gives the holder as V tal under CNPJ 02.041.460/0001-93, and the same holder and the same CNPJ appear on AS8167, the old Brasil Telecom number registered in November 1999, so both halves of the former Oi backbone now sit with one company. The IPv4 blocks are LACNIC allocations to that entity, with 187.76.0.0/16 recorded on 1 July 2009. Their IRR route objects are maintained under MAINT-AS52320, the maintainer tied to AS52320, which the registry names as GlobeNet Cabos Submarinos Colombia S.A.S.
- Provider
- V.tal
- Primary ASN
- AS7738
- Category
- ISP
- Headquarters
- Rio de Janeiro, Brazil
- Announced IPv4 prefixes
- 200
- Registry
- LACNIC
Known IP ranges
These prefixes are currently announced to the global routing table by AS7738 (AS7738 - V tal). Prefix sets change over time - use WHOIS Lookup for the authoritative record on any specific address.
187.76.0.0/16
187.125.0.0/16
201.59.0.0/16
200.151.0.0/16
200.164.0.0/16
189.80.0.0/16
200.216.0.0/16
187.12.0.0/16
200.223.0.0/16
200.195.0.0/17
2804:d40::/28
2804:13c::/32 (IPv6)
What does a V.tal IP mean in a privacy test?
An address on AS7738 is a Brazilian fixed line, but the company that sold the service to whoever is behind it may well not be V.tal. This is a wholesale network by design: V.tal builds the fibre and lets other providers sell over it. Its own retail customers do not carry the V.tal name either, because when the purchase of Oi's broadband unit closed on 28 February 2025 the base was relaunched the following month as a separate subsidiary, Nio, which started with roughly four million customers. So a lookup returning V.tal answers who owns the fibre and the address block, not who holds the contract, and those are routinely different parties. For a leak test the practical reading is a residential or small-business fixed connection somewhere in Brazil, sitting in a LACNIC allocation that predates the current company name by more than a decade, which is why the reverse-DNS names on it still describe an operator that no longer exists.
Where V.tal's address data actually lives
V.tal has no geofeed and no public allowlist. Its machine-readable record is the LACNIC allocation served through registro.br, and for 187.76.0.0/16 that object gives an owner of V tal under the CNPJ, a registration date of 1 July 2009, an abuse contact of abuse@vtal.com, and a technical contact still filed under the Telemar network management centre at ld-numeracaoip@vtal.com. The most operationally useful field in it is the reverse delegation: the block's nameservers are listed as ns9.telemar.net.br, ns2.telemar.net.br and ns4.telemar.net.br, which is the registry telling you in advance which zone will answer a lookup on any address inside it.
The routing side is IRR route objects rather than a document. The ones covering this space are described as Vtal Prefix with origin AS7738 and a contact of bgp@vtal.com, registered under MAINT-AS52320. They are not a clean picture. The same /16 also carries route objects for 187.76.66.0/23, 187.76.68.0/23 and 187.76.79.0/24 with the description CS-27719 TP, an origin of AS17072 - Total Play Telecomunicaciones, a Mexican operator - and the unrelated maintainer MAINT-AS32098. None of those three is announced: a lookup on any of them falls back to 187.76.64.0/18 originated by AS7738. An IRR-only check on this network will therefore hand you an origin AS in the wrong country that routes nothing, so confirm against what is actually in the table. The AS-SET V.tal names in PeeringDB is AS-OINETBR, the Oi name once again, and the entry lists its alternates as Telemar, Pegasus, Oi and Vtal while pointing readers at AS8167 as well.
Whose subscriber sits behind a V.tal address
Reverse DNS on this network is entirely inherited. One convention writes the four octets concatenated and zero-padded with no separators at all, so 187.76.10.5 becomes 18776010005.telemar.net.br. Another, on the space that carried Oi's old ADSL brand, hyphenates them under a user label: 200-164-10-5.user.veloxzone.com.br. Other blocks in the same allocation return nothing. None of those names distinguishes a retail subscriber from a partner provider's customer, because all of them are generated from the address rather than assigned to anyone, and they answer whether or not a host is there.
Routing is where the distinction actually appears. If the address falls inside a more specific prefix originated by a different AS number, that network is the retail provider and the one to contact; if the only route covering it is the large prefix announced by AS7738, the line terminates on V.tal's own network and abuse goes to the address on the LACNIC object. Whois will not help with this, because the allocation names V.tal for the entire block and a reseller's identity never reaches it. Nothing published states which pools are shared between customers or whether a given address will accept an inbound connection, so neither can be inferred from the registry or from a hostname that resolves.
Related tools
Frequently asked questions
Is V.tal the same network as Oi?
It is the network Oi used to run. AS7738 was Oi's Telemar backbone and the registro.br record now shows the holder as V tal; the old Brasil Telecom number, AS8167, is registered to the same company under the same CNPJ. The sale of Oi's broadband unit to V.tal closed on 28 February 2025, and that retail base now trades under a separate brand, Nio.
What does a V.tal result mean in a leak test?
An address on AS7738 is a Brazilian fixed line, but the company that sold the service to whoever is behind it may well not be V.tal. This is a wholesale network by design: V.tal builds the fibre and lets other providers sell over it. Its own retail customers do not carry the V.tal name either, because when the purchase of Oi's broadband unit closed on 28 February 2025 the base was relaunched the following month as a separate subsidiary, Nio, which started with roughly four million customers. So a lookup returning V.tal answers who owns the fibre and the address block, not who holds the contract, and those are routinely different parties. For a leak test the practical reading is a residential or small-business fixed connection somewhere in Brazil, sitting in a LACNIC allocation that predates the current company name by more than a decade, which is why the reverse-DNS names on it still describe an operator that no longer exists.
Why do V.tal addresses resolve to telemar.net.br?
Because the reverse zones were never renamed. The LACNIC record for the block lists its nameservers as ns9, ns2 and ns4 under telemar.net.br, so names such as 18776010005.telemar.net.br are the current, authoritative answer even though Telemar is no longer the operating brand.
Which internet provider is actually behind a V.tal address?
Whois will not say, because the allocation names V.tal for the whole block. Check the routing instead: an address inside a more specific prefix announced by another AS number belongs to that provider, while an address covered only by V.tal's own announcement is on its network directly.
Does V.tal publish a geofeed or an allowlist?
Neither. There is no geofeed attribute on the LACNIC object and no published file of ranges. What the registry does give is the abuse and BGP contacts at vtal.com and the reverse-DNS delegation, which tells you which zone will answer for the block before you query it.