IP Intelligence Briefing: 87.236.176.177
Date: 2026-06-06
---
**1. Core Profile**
- Risk Score: 40 (Moderate Risk)
- Ownership:
- ASN: 211298
- Organization: Driftnet Hostmaster (UK)
- Subnet: 87.236.176.0/24
- Geolocation:
- Country: United Kingdom (GB)
- City: London
- Latitude/Longitude: 55.38°N, -3.44°E
- Network Role:
- Single-service host (HTTP on port 80)
- No CDN, VPN, or mobile carrier indicators
---
**2. Threat & Activity**
- Threat Indicators: None detected (no malware, spam, or known attacker associations).
- DNS:
- Resolves to `r3-177-b1.monitoring.internet-measurement.com` (SPF/DMARC compliant).
- No malicious domains or email auth issues.
- BGP:
- Route stable (AS Path: 6939 211298).
- DNSSEC valid, no RPKI issues.
---
**3. Historical Observations**
- Signal Trends:
- 28 observations over 30 days (last 30 days).
- DNS and routing signals dominate; no significant threat persistence.
- Risk Stability:
- No spikes in abuse confidence or malicious activity.
---
**4. Network Relationships**
- DNS Associations:
- Linked to `internet-measurement.com` (likely benign research infrastructure).
- Subnet:
- Shared network (UK-DRIFTNET-20050831) with 175 IPs.
- 32 active siblings, 63 flagged as high-risk.
---
**5. Neighborhood Analysis**
- Subnet Abuse Density: 4% (low).
- Neighbor Risks:
- 4 high-risk IPs, 75 medium-risk IPs, 21 low-risk IPs.
- Most neighbors have moderate risk scores (40β60).
---
**6. Recommended Actions**
- Firewall Blocking:
- `iptables -A INPUT -s 87.236.176.177 -j DROP`
- `nft add rule inet filter input ip saddr 87.236.176.177 drop`
- Monitoring:
- Track DNS resolution patterns to `internet-measurement.com`.
- Monitor subnet for emerging risks (63 high-risk siblings).
---
**Summary**
The IP is a low-to-moderate risk host operated by Driftnet Hostmaster in London, UK. While no direct malicious activity is detected, its subnet contains 63 high-risk IPs. The DNS association with `internet-measurement.com` suggests benign research infrastructure, but further investigation into the subnetβs activity is advised. Implement firewall rules to block the IP if it aligns with your security policies.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Driftnet Hostmaster |
| ASN | AS211298 |
| Network Name | β |
| CIDR Block | 87.236.176.0/24 |
| RIR | RIPE |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | r3-177-b1.monitoring.internet-measurement.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | r3-177-b1.monitoring.internet-measurement.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| Closed Ports | 22, 25, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 27% | 2 | 3 |
| services | 24% | 2 | 3 |
| ownership | 30% | 3 | 4 |
| reputation | 22% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 26% | 12 | 20 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-11 15:05:48 UTC |
| Last Seen | 2026-06-26 11:22:47 UTC |
| Profile Built | 2026-06-26 11:26:54 UTC |
| Data Freshness | Live |
| Signal Types | 27 |
| Total Observations | 27 |
Full dossier details are available via our API.