IPDEBRIEF INTELLIGENCE BRIEFING
Target: 87.241.156.191/32
Classification: Low Risk / Passive Infrastructure
Date: 2026-07-28
---
EXECUTIVE SUMMARY
IP 87.241.156.191 is a low-risk infrastructure address (risk score: 25) belonging to TELECOM-ARMENIA (ASN 12297). The IP is currently firewalled with no open services. While the profile indicates low risk, geolocation data shows notable inconsistencies between US and Armenia assignments, warranting continued observation.
---
OWNERSHIP & NETWORK CLASSIFICATION
- ASN: 12297 (TELECOM-ARMENIA - Telecom Armenia OJSC, AM)
- Organization: ARMENTEL-MNT / VEON-AM-BB-NET
- CIDR Block: 87.241.128.0/19
- RIR: RIPE
- Registration: 2005-07-07
- Network Role: Provider infrastructure (firewalled, no services exposed)
---
GEOLLOCATION ANALYSIS
Critical Discrepancy Detected:
- Profile Location: New York, US (US-NY)
- Historical Location: Yerevan, Armenia (AM)
- Conclusion: Significant geolocation inconsistency suggests either IP reassignment or conflicting geolocation databases. The ASN and historical data align with Armenia, making the US assignment questionable.
---
THREAT POSTURE
- Risk Score: 25/100 (Low)
- Abuse Confidence: Not quantified in profile
- Blacklist Status: Listed on 1 of 8 DNSBLs (signal_type_id 2344)
- Threat Indicators: None detected
- Known Campaigns: None
- Tor Exit/Proxy: Not identified
- DNSSEC: Valid (true)
---
NEIGHBORHOOD CONTEXT (87.241.156.0/24)
- Abuse Density: 0 (Clean classification)
- Active Siblings: 1 of 2 total
- Risk Distribution: 1 medium-risk neighbor (87.241.156.87, risk: 40), 0 high-risk
- Inherited Risk: 0
- Assessment: Subnet is relatively clean with minimal abuse activity
---
OBSERVATION HISTORY (13 records)
Recent signals indicate:
- Stable ASN: Consistently linked to ASN 12297
- Geolocation Volatility: Conflicting location data between US and Armenia
- Blacklisting: Evidence of DNSBL listings (severity: high)
- DNS: DNSSEC valid, PTR hostnames empty
- Threat Persistence: 0 days (no persistent malicious activity detected)
---
RELATIONSHIP GRAPH
- Same Network: Multiple entries linking to VEON-AM-BB-NET
- External Relationships: None detected
- Associated Hostnames/Certificates: None identified
---
RECOMMENDED ACTIONS
- Immediate: Monitor for service exposure changes
- Firewall: No specific rules recommended (risk score: 25)
- Investigation Priority: Medium (due to geolocation inconsistency)
- Monitoring: Track geolocation changes and blacklist status updates
---
INTEL GAPS & RECOMMENDATIONS
1. Verify Geolocation: Investigate the US vs. Armenia discrepancy through additional passive data sources
2. Monitor Neighbor: Track 87.241.156.87 (risk: 40) for potential correlated activity
3. DNSBL Review: Examine specific blacklist listings contributing to the 1/8 listing ratio
4. Periodic Reassessment: Monitor for service exposure changes that may alter threat posture
---
END OF BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | ARMENTEL-MNT |
| ASN | AS12297 |
| Network Name | VEON-AM-BB-NET |
| CIDR Block | 87.241.128.0/19 |
| RIR | RIPE |
| Country | AM |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS12297 |
| Network Prefix | 87.241.128.0/18 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 38% | 2 | 5 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 23% | 2 | 4 |
| reputation | 33% | 1 | 5 |
| geolocation | 12% | 2 | 2 |
| Overall | 21% | 10 | 19 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-16 16:44:39 UTC |
| Last Seen | 2026-09-05 21:38:06 UTC |
| Profile Built | 2026-09-05 21:41:22 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 29 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 87.241.156.191
Who owns the IP address 87.241.156.191?
87.241.156.191 is registered to ARMENTEL-MNT. The address falls within the 87.241.128.0/19 network block. Registration is held at RIPE.
Where is 87.241.156.191 located?
Geolocation data places 87.241.156.191 in New York, US-NY, United States. The local time zone is America/New_York. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 87.241.156.191 malicious or safe?
87.241.156.191 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.