IPDebrief

87.236.176.215

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

IP Intelligence Briefing: 87.236.176.215

Date: 2026-06-06

---

**Risk Profile**

---

**Observation History**

- Stable routing (no recent BGP changes).

- Consistent geolocation in London, UK.

- HTTP service (port 80) observed with a 302 redirect.

- No persistent malicious activity detected over 28 observations.

- Low threat persistence (0 days of sustained risk).

---

**Network Relationships**

- Linked to `r3-215-d7.monitoring.internet-measurement.com` (valid SPF/DMArc).

- Shares subnet with 176 IPs (40 active, 64 flagged as high-risk).

- Part of the *UK-DRIFTNET-20050831* network (Driftnet Hostmaster).

- BGP path: `34549 6939 211298` (stable, no route anomalies).

---

**Neighborhood Analysis**

- 4 high-risk IPs (4%), 75 medium-risk IPs (75%), 21 low-risk IPs (21%).

- IPs like `87.236.176.2`, `87.236.176.3`, and `87.236.176.4` share similar risk profiles.

- 64 neighbors flagged for abuse (4% of subnet).

---

**Actionable Insights**

1. Monitor Subnet: The subnet contains a mix of risks, with 64 IPs flagged for abuse. Prioritize monitoring high-risk neighbors.

2. Verify DNS Activity: Investigate the DNS association with `internet-measurement.com` for potential benign or malicious intent.

3. Network Segmentation: Consider isolating this subnet if it hosts critical assets, given the presence of high-risk IPs.

4. Geolocation Validation: Confirm the IPโ€™s London, UK location with additional geolocation sources due to a 500km accuracy radius.

---

Conclusion: This IP appears benign but is part of a subnet with mixed risk. No immediate action is required, but ongoing monitoring of the subnet and its neighbors is recommended.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฌ๐Ÿ‡ง United Kingdom
Regionโ€”
CityLondon
TimezoneEurope/London
Latitude51.50
Longitude-0.12

๐Ÿข Ownership & Registration

OrganizationDriftnet Hostmaster
ASNAS211298
Network Nameโ€”
CIDR Block87.236.176.0/24
RIRRIPE
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRr3-215-d7.monitoring.internet-measurement.com
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnamesr3-215-d7.monitoring.internet-measurement.com

๐Ÿ” DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeSingle-Service Host
Network TierTier 3 โ€” Basic operator with some routing infrastructure
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
Closed Ports22, 25, 443, 3389, 8080, 8443 (1 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
22%
24
routing
27%
23
services
22%
24
ownership
24%
34
reputation
19%
13
geolocation
19%
22
Overall22%1220
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-12 09:41:53 UTC
Last Seen2026-06-26 17:30:43 UTC
Profile Built2026-06-26 17:35:50 UTC
Data FreshnessLive
Signal Types26
Total Observations28
๐Ÿ” 26 signal types ยท 28 observations collected
This report is generated from 26+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.