IPDebrief

190.181.87.95

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 190.181.87.95/32

Classification: Moderate Risk | Report Date: Current

Analyst: IPDebrief Intelligence Team

---

## Executive Summary

IP address 190.181.87.95 presents a moderate risk profile (score: 55/100) with no evidence of active malicious behavior. The IP is assigned to MicrolanOeste.net srl (AS52251) and geolocated to Merlo, Buenos Aires, Argentina. Network role classification indicates the IP is firewalled with no active services. While the immediate threat indicators are low, the IP resides in a subnet with elevated abuse density (6.2%), warranting enhanced monitoring.

---

## Technical Profile

AttributeValue
**IP Address**190.181.87.95
**Risk Score**55 (Moderate)
**ASN**52251 (MicrolanOeste.net srl)
**CIDR Block**190.181.84.0/22
**Geolocation**Argentina, Buenos Aires, Merlo
**Service Status**Firewalled / No Services
**Open Ports**None detected
**DNSBL Listings**3 of 8 lists
**Tor Exit Node**No
**Known Attacker**No

---

## Neighborhood Risk Assessment (190.181.87.0/24)

The /24 subnet contains 17 sibling IPs with the following risk distribution:

Abuse Density: 6.2% (1 threat sibling identified)

Active Siblings: 7

The elevated abuse density in this subnet suggests coordinated or adjacent malicious activity. While 190.181.87.95 shows no direct threat indicators, proximity to high-risk neighbors increases contextual risk.

---

## Historical Observations

Sixteen signal observations recorded. Key findings:

---

## Relationship Graph

No external entity relationships detected beyond same-network associations. The IP is not associated with known hostnames, organizations, or SSL certificates.

---

## Recommended Security Actions

Priority: Monitor

Rationale: Elevated risk score (55/100) with subnet context suggesting potential coordinated abuse.

Actions:

1. Increase logging verbosity for this IP and monitor recent activity patterns

2. Implement blocking rules across perimeter defenses (see below)

Firewall Rules

PlatformRule
iptables`iptables -A INPUT -s 190.181.87.95 -j DROP`
nftables`nft add rule inet filter input ip saddr 190.181.87.95 drop`
nginx`deny 190.181.87.95;`
pfSenseAdd to blocked IPs: `190.181.87.95/32`
Cloudflare WAFBlock via expression: `ip.src eq 190.181.87.95`
AWS WAFAdd IP set: `190.181.87.95/32`

---

## Intelligence Conclusion

190.181.87.95 does not exhibit active malicious indicators but operates within a subnet showing elevated abuse density. The absence of open services, Tor association, or known campaign links reduces immediate threat level. However, the moderate risk score and subnet context recommend defensive blocking and enhanced logging. SOC analysts should monitor for pattern changes and consider broader subnet-level monitoring for 190.181.84.0/22.

Threat Level: Moderate

Action Required: Implement block rules and increase monitoring

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇦🇷 Argentina
RegionBuenos Aires
CityMerlo
Timezone—
Latitude-34.66
Longitude-58.73

🏢 Ownership & Registration

OrganizationMicrolanOeste.net srl
ASNAS52251
Network Name190.181.84.0 - 190.181.87.255
CIDR Block190.181.84.0/22
RIRLACNIC
CountryAR
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)

🔐 DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierUnknown — Insufficient routing data to classify
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
443httpstcp—
Closed Ports22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned)
ServerWeb server detected
HTTP Title—

🔐 TLS Certificate

An expired certificate for E=support@ubnt.com, CN=UBNT-FC:EC:DA:9A:BA:BA, OU=Technical Support, O=Ubiquiti Networks Inc., L=San Jose, S=CA, C=US was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.
⚠️
E=support@ubnt.com, CN=UBNT-FC:EC:DA:9A:BA:BA, OU=Technical Support, O=Ubiquiti Networks Inc., L=San Jose, S=CA, C=US
Issued by E=support@ubnt.com, CN=UBNT-FC:EC:DA:9A:BA:BA, OU=Technical Support, O=Ubiquiti Networks Inc., L=San Jose, S=CA, C=US
Self-signed: Yes
SANsNone
Valid From2017-10-17T14:22:00+00:00
Valid Until2022-10-17T14:22:00+00:00 (expired)
TLS ProtocolTls12
Cipher SuiteTLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period1826 days

🛡️ Public Network Snapshot

Origin ASNAS52251
Network Prefix190.181.87.0/24
Route mappingFound
HSTSNot detected
CSPNot detected
HTTP/2Not detected

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
28%
23
routing
16%
12
services
8%
11
ownership
17%
23
reputation
11%
12
geolocation
12%
22
Overall15%913
Coverage: 6/6 dimensions · Data sufficiency: sufficient
Data CoherenceMixed Signals (68%) — 2 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Geo sources disagree on country: US, AR
⚠ TLS certificate claims US but primary geo says AR

📅 Observation Timeline 🔄 Live

First Seen2026-07-03 16:58:00 UTC
Last Seen2026-08-28 09:54:10 UTC
Profile Built2026-08-29 02:57:21 UTC
Data FreshnessLive
Signal Types21
Total Observations24
🔍 21 signal types · 24 observations collected
This report is generated from 21+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 190.181.87.95

Who owns the IP address 190.181.87.95?

190.181.87.95 is registered to MicrolanOeste.net srl. The address falls within the 190.181.84.0/22 network block. Registration is held at LACNIC.

Where is 190.181.87.95 located?

Geolocation data places 190.181.87.95 in Merlo, Buenos Aires, Argentina. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 190.181.87.95 malicious or safe?

190.181.87.95 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.

What ports are open on 190.181.87.95?

Responsive ports observed on 190.181.87.95 include 443. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.

🏘️ Related IP Addresses

Nearby addresses in 190.181.84.0/22

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.