# IP Intelligence Briefing: 190.181.87.95/32
Classification: Moderate Risk | Report Date: Current
Analyst: IPDebrief Intelligence Team
---
## Executive Summary
IP address 190.181.87.95 presents a moderate risk profile (score: 55/100) with no evidence of active malicious behavior. The IP is assigned to MicrolanOeste.net srl (AS52251) and geolocated to Merlo, Buenos Aires, Argentina. Network role classification indicates the IP is firewalled with no active services. While the immediate threat indicators are low, the IP resides in a subnet with elevated abuse density (6.2%), warranting enhanced monitoring.
---
## Technical Profile
| Attribute | Value |
|---|---|
| **IP Address** | 190.181.87.95 |
| **Risk Score** | 55 (Moderate) |
| **ASN** | 52251 (MicrolanOeste.net srl) |
| **CIDR Block** | 190.181.84.0/22 |
| **Geolocation** | Argentina, Buenos Aires, Merlo |
| **Service Status** | Firewalled / No Services |
| **Open Ports** | None detected |
| **DNSBL Listings** | 3 of 8 lists |
| **Tor Exit Node** | No |
| **Known Attacker** | No |
---
## Neighborhood Risk Assessment (190.181.87.0/24)
The /24 subnet contains 17 sibling IPs with the following risk distribution:
- High Risk: 1 IP (190.181.87.211, risk score: 80)
- Medium Risk: 6 IPs (including 190.181.87.5, .43, .65, .66, .74 at score 55)
- Low Risk: 9 IPs
Abuse Density: 6.2% (1 threat sibling identified)
Active Siblings: 7
The elevated abuse density in this subnet suggests coordinated or adjacent malicious activity. While 190.181.87.95 shows no direct threat indicators, proximity to high-risk neighbors increases contextual risk.
---
## Historical Observations
Sixteen signal observations recorded. Key findings:
- Recent subnet classification: "mostly_clean" (5.88% abuse density)
- ASN AS52251 flagged with 1 threat pulse via AlienVault OTX
- Geolocation confidence moderate (0.52) with multi-signal inference
- No persistent malicious behavior detected
- Ownership changes: 0 (stable)
---
## Relationship Graph
No external entity relationships detected beyond same-network associations. The IP is not associated with known hostnames, organizations, or SSL certificates.
---
## Recommended Security Actions
Priority: Monitor
Rationale: Elevated risk score (55/100) with subnet context suggesting potential coordinated abuse.
Actions:
1. Increase logging verbosity for this IP and monitor recent activity patterns
2. Implement blocking rules across perimeter defenses (see below)
Firewall Rules
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 190.181.87.95 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 190.181.87.95 drop` |
| nginx | `deny 190.181.87.95;` |
| pfSense | Add to blocked IPs: `190.181.87.95/32` |
| Cloudflare WAF | Block via expression: `ip.src eq 190.181.87.95` |
| AWS WAF | Add IP set: `190.181.87.95/32` |
---
## Intelligence Conclusion
190.181.87.95 does not exhibit active malicious indicators but operates within a subnet showing elevated abuse density. The absence of open services, Tor association, or known campaign links reduces immediate threat level. However, the moderate risk score and subnet context recommend defensive blocking and enhanced logging. SOC analysts should monitor for pattern changes and consider broader subnet-level monitoring for 190.181.84.0/22.
Threat Level: Moderate
Action Required: Implement block rules and increase monitoring
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | MicrolanOeste.net srl |
| ASN | AS52251 |
| Network Name | 190.181.84.0 - 190.181.87.255 |
| CIDR Block | 190.181.84.0/22 |
| RIR | LACNIC |
| Country | AR |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | — |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
E=support@ubnt.com, CN=UBNT-FC:EC:DA:9A:BA:BA, OU=Technical Support, O=Ubiquiti Networks Inc., L=San Jose, S=CA, C=US was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.| SANs | None |
| Valid From | 2017-10-17T14:22:00+00:00 |
| Valid Until | 2022-10-17T14:22:00+00:00 (expired) |
| TLS Protocol | Tls12 |
| Cipher Suite | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 1826 days |
🛡️ Public Network Snapshot
| Origin ASN | AS52251 |
| Network Prefix | 190.181.87.0/24 |
| Route mapping | Found |
| HSTS | Not detected |
| CSP | Not detected |
| HTTP/2 | Not detected |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 3 |
| routing | 16% | 1 | 2 |
| services | 8% | 1 | 1 |
| ownership | 17% | 2 | 3 |
| reputation | 11% | 1 | 2 |
| geolocation | 12% | 2 | 2 |
| Overall | 15% | 9 | 13 |
| Data Coherence | Mixed Signals (68%) — 2 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
⚠ TLS certificate claims US but primary geo says AR
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-03 16:58:00 UTC |
| Last Seen | 2026-08-28 09:54:10 UTC |
| Profile Built | 2026-08-29 02:57:21 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 24 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 190.181.87.95
Who owns the IP address 190.181.87.95?
190.181.87.95 is registered to MicrolanOeste.net srl. The address falls within the 190.181.84.0/22 network block. Registration is held at LACNIC.
Where is 190.181.87.95 located?
Geolocation data places 190.181.87.95 in Merlo, Buenos Aires, Argentina. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 190.181.87.95 malicious or safe?
190.181.87.95 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 190.181.87.95?
Responsive ports observed on 190.181.87.95 include 443. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.