IPDebrief

187.102.16.206

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# Threat Intelligence Briefing: 187.102.16.206

## Executive Summary

IP address 187.102.16.206 is classified as a High Risk residential endpoint associated with Brazilian telecommunications provider GHNET TELECOM LTDA. While the subnet demonstrates low overall abuse density, the target IP exhibits elevated risk characteristics with DNSBL listings and a 70-point risk score.

---

## Network Classification & Ownership

AttributeValue
ASN53094 (GHNET TELECOM LTDA)
Network Block187.102.16.0/20
CIDR Classification187.102.16.206/32
Infrastructure TypeResidential Endpoint
CountryBrazil (BR)
RegionMinas Gerais
CityGuanhães
RIRLACNIC

The IP resolves to PTR hostname `187-102-16-206.ghnet.com.br` with forward DNS confirmation.

---

## Risk Assessment

Risk Indicators:

---

## Threat Intelligence Findings

No active threat indicators or campaign correlations identified. The IP shows no evidence of persistent malicious activity or association with known threat actors.

---

## Neighborhood Analysis (187.102.16.0/24)

MetricValue
Subnet Abuse Density0% (Clean)
Total Siblings5
Active Siblings2
Threat Siblings0

Notable Neighbors:

The subnet demonstrates low abuse density overall, though several neighbor IPs exhibit elevated risk scores (45-70).

---

## Observation History

Recent monitoring activity shows 15 observations with signals including:

No ownership changes or persistent threat persistence patterns detected.

---

## Recommended Actions

Based on the risk profile and DNSBL listings, the following mitigations are recommended:

1. Monitor: Flag for enhanced monitoring due to 70-point risk score and DNSBL presence

2. Rate Limit: Apply connection rate limiting to mitigate potential residential endpoint abuse

3. Geo-Filtration: Consider geo-blocking if traffic from this IP is not legitimate for your operations

4. DNSBL Verification: Investigate specific blacklist listings to determine cause of reputation degradation

---

## Intelligence Conclusion

This residential IP presents a moderate-high risk profile primarily driven by DNSBL listings rather than active malicious behavior. The subnet environment appears relatively clean, suggesting the risk is localized to this endpoint. Recommend monitoring for any escalation in threat indicators while applying standard residential endpoint protection measures.

Threat Level: MODERATE

Recommended Priority: MONITOR

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇧🇷 Brazil
RegionMinas Gerais
CityGuanhães
Timezone—
Latitude-18.78
Longitude-42.93

🏢 Ownership & Registration

OrganizationGHNET TELECOM LTDA
ASNAS53094
Network Name136912
CIDR Block187.102.16.0/20
RIRLACNIC
CountryBR
Abuse Contact—

🌐 DNS Intelligence

PTR187-102-16-206.ghnet.com.br
Forward ConfirmedYes — FCrDNS verified
Forward Hostnames187-102-16-206.ghnet.com.br

🔐 DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureResidential
Service PurposeResidential Endpoint
Network TierEnd-User — Residential ISP endpoint
Residential

🔌 Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Server—
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS53094
Network Prefix187.102.16.0/23
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
0%
00
routing
25%
11
services
25%
11
ownership
0%
00
reputation
0%
00
geolocation
0%
00
Overall8%22
Coverage: 2/6 dimensions · Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

📅 Observation Timeline 🔄 Live

First Seen2026-07-06 12:08:44 UTC
Last Seen2026-09-19 19:50:33 UTC
Profile Built2026-09-11 09:44:27 UTC
Data FreshnessLive
Signal Types17
Total Observations21
🔍 17 signal types · 21 observations collected
This report is generated from 17+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 187.102.16.206

Who owns the IP address 187.102.16.206?

187.102.16.206 is registered to GHNET TELECOM LTDA. The address falls within the 187.102.16.0/20 network block. Registration is held at LACNIC.

Where is 187.102.16.206 located?

Geolocation data places 187.102.16.206 in Guanhães, Minas Gerais, Brazil. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 187.102.16.206 malicious or safe?

187.102.16.206 currently carries a high risk assessment, meaning indicators associated with malicious or abusive activity have been observed. This assessment is generated from continuously collected signals and can change over time.

What is the hostname for 187.102.16.206?

The reverse DNS (PTR) record for 187.102.16.206 is 187-102-16-206.ghnet.com.br. This hostname is forward-confirmed, meaning it resolves back to the same address.

Is 187.102.16.206 a VPN, proxy, or data center address?

187.102.16.206 is classified as a residential network based on network ownership and behavioural analysis.

🏘️ Related IP Addresses

Nearby addresses in 187.102.16.0/20

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.