IPDebrief

87.236.176.143

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# INTELLIGENCE BRIEFING: 87.236.176.143

## Executive Summary

IP 87.236.176.143 presents a moderate risk profile (Risk Score: 40) associated with Driftnet Hostmaster infrastructure in London, UK. The IP is currently firewalled with no open services detected, but operates within a subnet exhibiting elevated abuse density. Recommended action: implement blocking rules across perimeter defenses.

---

## Profile Overview

AttributeValue
**Risk Score**40 (Moderate Risk)
**Organization**Driftnet Hostmaster (ASN 211298)
**Location**London, GB
**Subnet**87.236.176.0/24
**Network Classification**Mixed / Firewalled
**RIR**RIPE

---

## Threat Indicators

---

## Network Context & Neighborhood Analysis

The IP resides in subnet 87.236.176.0/24 with the following characteristics:

Neighborhood sampling of 100 IPs shows risk distribution:

Neighboring IPs (87.236.176.2-6) exhibit risk scores ranging from 40-55, indicating a generally elevated-risk neighborhood.

---

## DNS & Network Role

---

## Observation History

19 observations recorded with signals from June 2026 timeframe. Recent signals indicate:

---

## Recommended Security Actions

Based on risk assessment, implement the following blocking rules:

iptables

```

iptables -A INPUT -s 87.236.176.143 -j DROP

```

nftables

```

nft add rule inet filter input ip saddr 87.236.176.143 drop

```

nginx

```

deny 87.236.176.143;

```

pfSense

```

87.236.176.143/32

```

Cloudflare WAF

```json

{

"description": "Block 87.236.176.143 โ€” IPDebrief risk score 40",

"action": "block",

"filter": {

"expression": "ip.src eq 87.236.176.143"

}

}

```

AWS WAF

```json

{

"Addresses": ["87.236.176.143/32"],

"Description": "IPDebrief risk 40"

}

```

---

## Intelligence Assessment

The IP demonstrates moderate-risk characteristics with DNSBL listings and elevated neighborhood abuse density. However, the absence of open services and known campaign associations reduces immediate threat severity. Blocking is recommended at perimeter controls, particularly given the subnet's 35% abuse density and 66 threat-sibling count. Monitor for service activation or reputation degradation.

---

*Report generated by IPDebrief Intelligence Platform. All data based on observed signals and third-party threat intelligence feeds.*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฌ๐Ÿ‡ง United Kingdom
Regionโ€”
CityLondon
TimezoneEurope/London
Latitude51.50
Longitude-0.12

๐Ÿข Ownership & Registration

OrganizationDriftnet Hostmaster
ASNAS211298
Network Nameโ€”
CIDR Blockโ€”
RIRRIPE
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRr3-143-8f.monitoring.internet-measurement.com
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnamesr3-143-8f.monitoring.internet-measurement.com

๐Ÿ” DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown โ€” Insufficient routing data to classify
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
24%
23
routing
13%
11
services
8%
11
ownership
20%
23
reputation
19%
13
geolocation
19%
22
Overall17%913
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-07 23:04:40 UTC
Last Seen2026-06-24 00:01:33 UTC
Profile Built2026-06-24 00:08:59 UTC
Data FreshnessLive
Signal Types20
Total Observations20
๐Ÿ” 20 signal types ยท 20 observations collected
This report is generated from 20+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.