IP Intelligence Briefing: 216.180.246.87
Date: 2026-06-07
---
**1. Risk Profile**
- Overall Risk Score: 25 (Low Risk)
- Provider/Authority Scores: 0/0
- Stability: Unstable (route stability flag inactive)
- Threat Indicators: No direct malicious activity detected (no blacklists, spam, or known attackers).
---
**2. Ownership & Geolocation**
- ASN: 396982 (Private Customer, ARIN-regulated)
- Geolocation:
- Country: United States
- City: Massy (coordinates unconfirmed)
- Subnet: 216.180.246.0/24
- Network Role: Unknown (no CDN, cloud, or residential indicators).
---
**3. Threat Observations**
- Proxycheck.io: Marked as a compromised server (confidence: 85%) with proxy-type "Compromised Server."
- Alienvault-OTX: Detected 35 pulses linked to potential threats (confidence: 95%), though no specific campaigns or malware families are tied to this IP.
- No DNS-Based Threats: No malicious domains, email auth issues, or CAA mismatches.
---
**4. Network Relationships**
- DNS Associations:
- `crawler087.deepfield.net` (PTR record confirmed).
- Subnet Peers:
- Shared subnet `NET-216-180-246-0-24` with 13 sibling IPs (3 active, 0 malicious).
- No Known Malicious Relationships: No connections to known C2 servers, botnets, or malicious organizations.
---
**5. Neighborhood Analysis**
- Subnet Abuse Density: 0% (clean classification).
- Neighbor Risk Distribution:
- Low Risk: 9 IPs (avg. score: 25).
- Medium Risk: 7 IPs (avg. score: 50).
- Notable Neighbors:
- `216.180.246.3` (risk: 50), `216.180.246.58` (risk: 50), `216.180.246.160` (risk: 50).
---
**6. Temporal Trends**
- Observation History:
- First recorded: 2026-05-29.
- No persistent malicious behavior (threat persistence: 0 days).
- Recent changes: Proxycheck.io flagged it as a compromised server (June 7).
---
**7. Recommendations**
- Monitor Subnet: Track medium-risk neighbors for potential lateral movement.
- Investigate Proxy Flags: Confirm if compromised server status is part of a larger network compromise.
- Check DNS Activity: Monitor `crawler087.deepfield.net` for suspicious behavior (e.g., scraping, data exfiltration).
- Verify Geolocation: Confirm coordinates for Massy, as current data is unverified.
---
Conclusion: This IP is low-risk but exhibits conflicting signals (proxy compromise vs. no direct threats). Further analysis of its subnet and DNS associations is recommended.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Private Customer |
| ASN | AS396982 |
| Network Name | NET-216-180-246-0-24 |
| CIDR Block | 216.180.246.0/24 |
| RIR | ARIN |
| Country | France |
| Abuse Contact | β |
π DNS Intelligence
| PTR | crawler087.deepfield.net |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | crawler087.deepfield.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 13% | 1 | 2 |
| geolocation | 27% | 2 | 2 |
| Overall | 20% | 10 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-14 01:09:41 UTC |
| Last Seen | 2026-06-07 01:57:12 UTC |
| Profile Built | 2026-06-07 02:01:16 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 21 |
Full dossier details are available via our API.