IP Intelligence Briefing: 87.106.29.220
Date: 2026-06-11
---
**Overview**
- Risk Score: 80 (High Risk)
- Provider: AS8560 (Ionos SE)
- Geolocation: France (FR), Latitude 48.54, Longitude 6.06
- Network Role: Firewalled / No Services
- Threat Indicators: No direct malicious activity detected
---
**Key Findings**
1. Ownership & Infrastructure
- Registered to AS8560-MNT (Ionos SE) under the fr-nbz-ionos-cloud-nbz netname.
- Located in France, with a stable geolocation profile.
- Firewalled network with no open services or TLS certificates detected.
2. DNS & Email Security
- PTR record resolves to ip87-106-29-220.pbiaas.com.
- Email security: SPF and DMARC records present, no email reputation risks.
3. Threat Observations
- 17 observations over 30 days:
- High-confidence signal (0.95) linked to a German ISP (AS8560) with 20 "pulses" (potential threat indicators).
- Basic operator score (0.26) suggests low trustworthiness.
- No direct malware, phishing, or spam campaigns detected.
4. Network Relationships
- Same subnet (87.106.29.0/24) with 1 risky neighbor (87.106.29.151, risk score 65).
- DNS associations with ip87-106-29-220.pbiaas.com (likely infrastructure-related).
5. Behavioral & Routing
- Traceroute shows 30 hops, with 21 timeouts; routed through Comcast networks.
- BGP stability: Route changes in the last 30 days (unstable).
---
**Actionable Insights**
- Monitor Subnet: The /24 subnet has 1 high-risk neighbor (87.106.29.151). Investigate potential lateral movement or shared infrastructure risks.
- Check DNS Hostname: Analyze pbiaas.com for domain-related threats (e.g., CNAME chains, malicious subdomains).
- Firewall Rules: Block or restrict traffic from this IP if it aligns with known malicious activity (e.g., C2 servers, data exfiltration).
- Threat Feeds: Cross-reference with threat intelligence platforms for any missed indicators (e.g., malware hashes, IOC lists).
---
**Conclusion**
This IP is part of a high-risk network managed by Ionos SE, with no direct malicious activity detected. However, its association with a German ISP and a risky subnet neighbor warrants further investigation. SOC teams should monitor for anomalies in DNS, routing, or subnet-level behavior.
Recommended Tools:
- Use `ipdebrief_actions` to generate firewall rules.
- Compare with neighboring IPs (e.g., 87.106.29.151) using `ipdebrief_compare`.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | AS8560-MNT |
| ASN | AS8560 |
| Network Name | fr-nbz-ionos-cloud-nbz |
| CIDR Block | 87.106.29.0/24 |
| RIR | RIPE |
| Country | FR |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | ip87-106-29-220.pbiaas.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | mail.sentinel-ai.co.uk |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | nginx/1.31.1 |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.2p1 Debian-2+deb12u10 |
๐ TLS Certificate
| SANs | admin.sentinel-ai.co.ukapex.sentinel-ai.co.uksentinel-ai.co.ukwww.sentinel-ai.co.uk |
| Valid From | 2026-06-07T12:27:02+00:00 |
| Valid Until | 2026-09-05T12:27:01+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
| Serial Number | 055922633341EF21FE04EAB631ECBA521C8E |
| Thumbprint | C9A844275AE6A621B592885A6201501EDCA3D734 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 13% | 1 | 1 |
| routing | 13% | 1 | 1 |
| services | 13% | 1 | 1 |
| ownership | 27% | 2 | 3 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 2 | 2 |
| Overall | 15% | 7 | 8 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-25 18:48:44 UTC |
| Last Seen | 2026-06-13 03:46:09 UTC |
| Profile Built | 2026-06-11 01:02:45 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 25 |
Full dossier details are available via our API.