Skip to content

IPv4 address

82.117.87.192

Last fetched

82.117.87.192 is announced in 82.117.87.0/24 by RU-AEZA-AS - Aeza Group LLC and geolocates to RU. 82.117.87.192 is listed by 2 threat feeds; reconciled level HIGH.

Threat posture

40threat score (procedure-native scale)

HIGH

Listed by 2 threat feeds. At least one source recommends blocking. Advisory: asn-bulletproof-context.

Categories: Phishing

Threat feeds listing this
2
Verdict coverage
malicious-evidenced
First seen on a feed
Wed, 26 Aug 2026 20:50:41 GMT
Last seen on a feed
Fri, 09 Oct 2026 00:11:41 GMT

Nutrition Label

WHISPER CANON · 82.117.87.192Routing diversity9.0/10Peering density5.1/10MOAS conflict✓ noneThreat-feed listings6.8/10WHOIS transparency—Resolver footprint—canon.whisper.security/ip/82.117.87.192

Attribution

Announced prefix
82.117.87.0/24
Announcing network
RU-AEZA-AS - Aeza Group LLC
RIR-registered prefix
82.117.64.0/19
RPKI
not-found

Abuse contact

Report abuse from 82.117.87.192 to the address block's holder first and copy the announcing network. These are the abuse contacts WhisperGraph holds for the block and the network.

Address block
lir@avantel.ru
Network (AS216246)
support@aeza.ru

Network context

Attributed threat actor
Dark Caracal

Anycast detection

This does not appear to be an anycast address on the three signals Canon evaluates: reverse DNS, announced-prefix width and the announcing network's peer count.

Reverse DNS

Geographic detail

City
Moscow, RU
Country
RU
Dominant city of the prefix
Moscow, RU

Threat-feed listings

Threat-feed evidence

History

Related pages

Pivot from 82.117.87.192 into the prefix, network and country that carry it.

Queries

This address's full card — routing attribution, reverse DNS and listed feeds.


MATCH (ip:IPV4 {name: $ip})
OPTIONAL MATCH (ip)-[:BELONGS_TO]->(rp:REGISTERED_PREFIX)
OPTIONAL MATCH (ip)-[:ANNOUNCED_BY]->(ap:ANNOUNCED_PREFIX)
OPTIONAL MATCH (a:ASN)-[:ROUTES]->(ap)
OPTIONAL MATCH (a)-[:HAS_NAME]->(an:ASN_NAME)
OPTIONAL MATCH (ip)-[:LOCATED_IN]->(city:CITY)
OPTIONAL MATCH (ip)-[:HAS_COUNTRY]->(ipc:COUNTRY)
WITH ip, rp, ap, a, an, city, ipc
LIMIT 10
WITH ip,
     collect(rp.name) AS registeredPrefixes,
     collect(rp.abuseEmail) AS registeredAbuseEmails,
     collect({prefix: ap.name, asn: a.name, network: an.name, isMoas: ap.isMoas, rpkiStatus: ap.rpkiStatus, isAnycast: ap.isAnycast, dominantCity: ap.dominantCity, abuseEmail: ap.abuseEmail, networkAbuseEmail: a.abuseEmail}) AS announcements,
     collect(city.name) AS cities,
     collect(ipc.name) AS countries,
     collect(a.name) AS announcerNames,
     head(collect(a)) AS primaryAsn,
     head(collect(ap)) AS primaryPrefix
OPTIONAL MATCH (primaryPrefix)-[:CONFLICTS_WITH]->(conflict:ASN)
WITH ip, registeredPrefixes, registeredAbuseEmails, announcements, cities, countries, announcerNames, primaryAsn,
     collect(conflict.name) AS conflictAsns
CALL { WITH primaryAsn MATCH (primaryAsn)-[:ROUTES]->(p:ANNOUNCED_PREFIX) RETURN count(p) AS asnPrefixCount }
CALL { WITH primaryAsn MATCH (primaryAsn)-[:BGP_NEIGHBOR]-(peer:ASN) RETURN count(peer) AS asnPeerCount }
RETURN ip.name AS name,
       ip.verdictLevel AS verdictLevel,
       ip.verdictScore AS verdictScore,
       ip.verdictBlocking AS verdictBlocking,
       ip.verdictCoverage AS verdictCoverage,
       ip.verdictAdvisory AS verdictAdvisory,
       ip.threatSources AS threatSources,
       ip.threatFirstSeen AS threatFirstSeen,
       ip.threatLastSeen AS threatLastSeen,
       ip.isTor AS isTor,
       ip.isVpn AS isVpn,
       ip.isProxy AS isProxy,
       ip.isC2 AS isC2,
       ip.isPhishing AS isPhishing,
       registeredPrefixes, registeredAbuseEmails, announcements, cities, countries, announcerNames, conflictAsns,
       asnPrefixCount, asnPeerCount
Run yourself →

Network context — Tor exit relays, attributed actors, and the covering blocks' signals, cloud region and vendor.


MATCH (ip:IPV4 {name: $ip})
OPTIONAL MATCH (ip)-[:OPERATES_EXIT_NODE]->(tor:TOR_RELAY)
WITH ip, count(tor) AS torRelays
OPTIONAL MATCH (ip)-[:ATTRIBUTED_TO]->(actor:ACTOR)
WITH ip, torRelays, collect(actor.name)[0..5] AS actors
OPTIONAL MATCH (ip)-[:BELONGS_TO]->(p:PREFIX)
WITH torRelays, actors, collect(p.name) AS coveringPrefixes
UNWIND (CASE WHEN size(coveringPrefixes) = 0 THEN [null] ELSE coveringPrefixes END) AS pn
OPTIONAL MATCH (cp:PREFIX {name: pn})
OPTIONAL MATCH (cp)-[:HAS_SIGNAL]->(sig:THREAT_SIGNAL_TYPE)
OPTIONAL MATCH (cp)-[:PREFIX_IN_REGION]->(reg:CLOUD_REGION)
OPTIONAL MATCH (cp)-[:DELEGATED_TO]->(v:VENDOR)
RETURN torRelays, actors,
       collect(sig.name) AS signals,
       collect(reg.name) AS regions,
       collect(v.name) AS vendors
Run yourself →

Or query Whisper from your own LLM workflow via the Whisper MCP server.