# IP Intelligence Briefing: 86.111.176.100/32
Classification: Moderate Risk
Report Date: Current
Analyst: SOC Intelligence Team
---
## Executive Summary
IP 86.111.176.100 is a moderate-risk (50/100) static residential IP address associated with the DIME-MNT organization (ASN 33182). The IP is currently firewalled with no active services, but exhibits concerning DNS blacklist activity and historical abuse patterns. While the immediate threat is contained, the IP warrants defensive measures due to its classification history and network context.
---
## Technical Profile
Network Attribution
- ASN: 33182 (DIME-MNT)
- RIR: RIPE
- BGP Prefix: 86.111.176.0/22
- Route Stability: Unstable (route changes detected)
- DNSSEC: Valid
Geolocation
- Country: United States (US)
- Accuracy Radius: 3,750 km (highly imprecise)
- Reverse DNS: 86-111-176-100.static.dimenoc.com
- Forward Resolution: Confirmed (1 hostname)
Service State
- Open Ports: None
- HTTP/HTTPS: No services detected
- TLS Certificates: None
- Classification: Firewalled / No Services
---
## Threat Assessment
Current Risk Indicators
- Risk Score: 50 (Moderate)
- DNSBL Listings: 2 of 8 total lists (active)
- Operator Score: 0.2174 (Minimal)
- Abuse Confidence: Not quantified
Known Threat Indicators
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Campaign Affiliation: None detected
Control Plane Anomalies
- RPKI State: Not evaluated
- IRR Consistency: Not evaluated
- Route Changes (30d): Active
- MOAS Detection: No
---
## Historical Analysis
Observation Count: 23 signals tracked
Recent Activity Timeline:
- 2026-06-25: Listed on 8 DNSBLs with "high" severity rating (confidence 0.85)
- 2026-06-24: Operator score assessment: "Minimal" (confidence 0.60)
- 2026-06-05: Initial subnet classification: "mostly_clean" (confidence 0.40)
Temporal Trends:
- Ownership changes: 0
- Threat observation count: 1
- Threat persistence days: 0
- Not classified as persistently malicious
---
## Network Context
Subnet Analysis (86.111.176.0/24)
- Abuse Density: 1 (profile indicates elevated activity)
- Classification: Mostly clean
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 1
Relationship Graph
- Total Relationships: 42
- Primary Network Association: HOSTDIME-7742 (repeated associations)
- Network Type: Same Network (multiple entries)
---
## Defensive Recommendations
Immediate Actions
Based on risk score 50 and DNSBL listings, the following rules are recommended:
| Platform | Rule |
|---|---|
| **iptables** | `iptables -A INPUT -s 86.111.176.100 -j DROP` |
| **nftables** | `nft add rule inet filter input ip saddr 86.111.176.100 drop` |
| **nginx** | `deny 86.111.176.100;` |
| **pfSense** | `86.111.176.100/32` |
| **Cloudflare WAF** | Block IP (risk score 50) |
| **AWS WAF** | Block 86.111.176.100/32 |
Intelligence Notes
- IP is currently inactive (no open ports) but retains blacklist presence
- Route instability suggests potential network reconfiguration or abuse migration
- Historical DNSBL activity warrants monitoring for recurrence
- Subnet-level threat sibling detectedβconsider broader subnet filtering if threat persists
---
## Conclusion
IP 86.111.176.100 represents a moderate-risk endpoint with no current active services but persistent DNS blacklist associations. The IP's network context (86.111.176.0/24) shows minimal abuse density but contains at least one threat-sibling. Recommended actions include blocking at perimeter firewalls and monitoring for renewed activity or subnet-level escalation.
Priority: Medium
Status: Block recommended
Review Frequency: Quarterly (monitor subnet activity)
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DIME-MNT |
| ASN | AS33182 |
| Network Name | β |
| CIDR Block | β |
| RIR | RIPE |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 86-111-176-100.static.dimenoc.com |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 86-111-176-100.static.dimenoc.com |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 24% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 33% | 2 | 4 |
| Overall | 24% | 10 | 18 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-09 05:26:26 UTC |
| Last Seen | 2026-06-26 18:11:39 UTC |
| Profile Built | 2026-06-25 14:23:51 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 25 |
Full dossier details are available via our API.