# IP Intelligence Briefing: 87.236.208.53/32
Date: Current Assessment
Classification: Moderate Risk
Risk Score: 40/100
## Executive Summary
IP address 87.236.208.53 presents a moderate risk profile (score 40) with notable inconsistencies in geolocation data. The address is registered to RIPE RIR under organization mrserver-mnt (AS214922) with a CIDR block of 87.236.208.0/24. No active services were detected on the target, though the IP appears in 2 of 8 DNSBL lists. Geographic validation shows conflicting reports placing the asset in Frankfurt (DE), Tehran (IR), and Manchester (GB), requiring further validation.
## Ownership & Registration
- ASN: 214922 (mrserver-mnt)
- Netname: mrserver
- Organization: mrserver-mnt
- RIR: RIPE
- CIDR Block: 87.236.208.0/24
- Abuse Contact: abuse@ariawebco.net
- Registration Date: Not available
## Network Classification
- Service Purpose: Firewalled / No Services
- Infrastructure Type: None detected
- Cloud/CDN/Proxy/Vpn: Negative on all checks
- Mobile/Residential: Negative
- Bogon/Anycast: Negative
## Threat Indicators
- Blacklist Count: 2
- DNSBL Listed: 2 of 8 total lists
- Is Known Attacker: False
- Is Spam Source: False
- Is Tor Exit: False
- Abuse Confidence Score: Not available
## Geolocation Discrepancies
Significant inconsistencies observed across multiple signal sources:
- Primary Report: Frankfurt, DE (Europe/Berlin)
- Secondary Report: Tehran, IR
- Tertiary Report: Manchester, ENG, GB
This geographic inconsistency (DE/IR/GB) suggests potential data pollution, proxy usage, or misconfigured infrastructure. Three geo sources report consensus disagreement.
## Neighborhood Assessment
- Subnet: 87.236.208.53/24
- Abuse Density: 0
- Classification: Clean
- Total Siblings: 1
- Threat Siblings: 0
- Active Siblings: 0
No neighboring threat activity detected in the /24 subnet.
## Historical Signal Analysis
Fourteen observations recorded. Key temporal signals:
- Recent threat indicators present (confidence 0.75)
- Ownership and ASN data inconsistent across observation periods
- Geographic reports fluctuate between DE, IR, and GB
- No persistent malicious behavior detected
## Relationship Graph
- Linked Entity: mrserver (Same Network)
- Relationship Type: Network association
## Recommended Security Actions
Based on risk profile and threat indicators, the following rules are recommended:
Firewall Rules:
- `iptables -A INPUT -s 87.236.208.53 -j DROP`
- `nft add rule inet filter input ip saddr 87.236.208.53 drop`
Application-Level Blocking:
- Nginx: `deny 87.236.208.53;`
- pfSense: Block 87.236.208.53/32
- Cloudflare WAF: Block IP with expression `ip.src eq 87.236.208.53`
- AWS WAF: Add 87.236.208.53/32 to blacklist
Operational Notes:
- IP is firewalled with no open services detected
- No active threat campaigns correlated
- Control plane shows route stability issues (isRouteStable: false)
- DNSSEC validation: Valid
## Intelligence Assessment
The moderate risk score (40) is primarily driven by DNSBL listings and geographic inconsistency rather than confirmed malicious activity. The absence of open services and clean neighborhood profile suggests this IP may be part of a broader infrastructure rather than an active attacker. However, the geographic discrepancies warrant continued monitoring for potential proxy or spoofing activity.
Recommendation: Implement blocking rules but prioritize additional validation on the geographic inconsistencies before escalating to threat incident status.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | mrserver-mnt |
| ASN | AS214922 |
| Network Name | mrserver |
| CIDR Block | 87.236.208.0/24 |
| RIR | RIPE |
| Country | IR |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256RSA |
| Validity Period | 83 days |
🛡️ Public Network Snapshot
| Origin ASN | AS214922 |
| Network Prefix | 87.236.208.0/24 |
| Route mapping | Found |
| HSTS | Not detected |
| CSP | Not detected |
| HTTP/2 | Enabled |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-21 00:44:28 UTC |
| Last Seen | 2026-09-02 23:47:12 UTC |
| Profile Built | 2026-09-02 23:51:23 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 25 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 87.236.208.53
Who owns the IP address 87.236.208.53?
87.236.208.53 is registered to mrserver-mnt. The address falls within the 87.236.208.0/24 network block. Registration is held at RIPE.
Where is 87.236.208.53 located?
Geolocation data places 87.236.208.53 in Frankfurt, ENG, Germany. The local time zone is Europe/Berlin. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 87.236.208.53 malicious or safe?
87.236.208.53 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.