IPDebrief

77.90.185.105

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 77.90.185.105/32

Classification: Moderate Risk | Date: 2026-06-26

---

## Executive Summary

IP address 77.90.185.105 presents a moderate security risk profile with an overall risk score of 55/100. The address is associated with LimitedNetwork-MNT (ASN 213790) and geolocated to the United Kingdom (GB). The IP shows no active services, no open ports, and is not currently flagged as a known attacker, Tor exit node, or spam source. However, the subnet environment exhibits mixed abuse density, and the IP is listed on multiple DNS blocklists.

---

## Technical Profile

AttributeValue
**Risk Score**55/100 (Moderate)
**Provider Score**0
**Authority Score**0
**Operator Score**0.1304
**Geolocation**GB, Europe/London (±750km accuracy)
**ASN**213790
**Organization**LimitedNetwork-MNT
**RIR**Ripe
**Network Block**77.90.185.0/24
**DNSSEC Status**Valid

---

## Threat Indicators

The IP does not exhibit persistent malicious behavior. Threat observation count remains at 1 with no evidence of persistent malicious activity.

---

## Network Environment Analysis

Subnet Characteristics (77.90.185.0/24)

Notable High-Risk Neighbors:

IP AddressRisk ScoreAuthority Score
77.90.185.168050
77.90.185.288050
77.90.185.378050
77.90.185.418050
77.90.185.2298050

The subnet shows a mixed risk profile with 12 threat-identified siblings, suggesting some level of neighborhood risk correlation that warrants monitoring.

---

## Service & DNS Analysis

The IP presents as a firewalled address with no detectable services or DNS records, indicating limited public exposure.

---

## Observation History

Sixteen signal observations recorded between 2026-06-05 and 2026-06-26. Recent observations show:

No significant escalation in risk profile observed over the monitoring period.

---

## Relationships

The IP maintains network-level relationships with the LIMITED-NETWORK organization, with fifteen recorded same-network associations. No cross-network or organizational relationships detected.

---

## Recommended Actions

Immediate Recommendations (High Severity)

Firewall Rules

```bash

# iptables

iptables -A INPUT -s 77.90.185.105 -j DROP

# nftables

nft add rule inet filter input ip saddr 77.90.185.105 drop

# nginx

deny 77.90.185.105;

```

Cloud/WAF Rules

---

## SOC Analyst Notes

The IP address 77.90.185.105 should be treated as a moderate-risk entity requiring monitoring. While not currently exhibiting active malicious behavior, the following contextual factors warrant attention:

1. Subnet Context: The /24 subnet contains multiple high-risk neighbors (5 IPs with risk score 80), indicating potential infrastructure sharing with higher-risk entities.

2. DNSBL Presence: Listed on 3 of 8 DNS blocklists, suggesting prior reputation issues.

3. No Active Services: The IP appears firewalled with no open ports, which may indicate either defensive hardening or egress-only configuration.

4. Monitoring Priority: Medium-high priority for logging and traffic analysis, particularly if the IP begins generating outbound traffic or if services become active.

Recommended Monitoring Duration: 30 days | Escalation Threshold: Risk score > 70 or DNSBL listing increase > 5

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฌ๐Ÿ‡ง United Kingdom
RegionUS-NY
CityNew York
TimezoneEurope/London
Latitude35.70
Longitude51.41

๐Ÿข Ownership & Registration

OrganizationLimitedNetwork-MNT
ASNAS213790
Network Nameโ€”
CIDR Blockโ€”
RIRRIPE
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)

๐Ÿ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierUnknown โ€” Insufficient routing data to classify
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
443httpstcpโ€”
Closed Ports22, 25, 3389, 8080, 8443 (2 open / 7 scanned)
ServerCaddy
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
24%
23
routing
13%
11
services
8%
11
ownership
24%
23
reputation
22%
13
geolocation
19%
22
Overall18%913
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-10 22:18:00 UTC
Last Seen2026-06-26 05:49:56 UTC
Profile Built2026-06-26 06:33:46 UTC
Data FreshnessLive
Signal Types17
Total Observations17
๐Ÿ” 17 signal types ยท 17 observations collected
This report is generated from 17+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.