# IP Intelligence Briefing: 109.207.35.178/32
## Executive Summary
IP address 109.207.35.178 is classified as High Risk (Risk Score: 70). The address is associated with TRUF network infrastructure in Serbia and shows no active open services. While the IP itself shows no direct threat indicators, it resides within a subnet containing 20 medium-risk neighbors, suggesting potential lateral threat activity.
## Network Profile
- IP Address: 109.207.35.178
- Risk Score: 70 (High Risk)
- Organization: AS6700-MNT / TRUF
- ASN: 52026
- Country: Serbia (RS)
- CIDR Block: 109.207.32.0/20
- Geolocation: Datacenter/ISP facility (www.kbcnet.rs)
- Network Role: Firewalled / No Services
- RIR: ARIN
## Threat Indicators
- Blacklist Count: 0
- DNSBL Listed: 4 of 8 total lists
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Open Ports: None detected
- Active Services: None detected
## Control Plane Analysis
- Origin ASN: 52026
- BGP Prefix: 109.207.35.0/24
- Route Stability: False (route changes detected)
- RPKI State: Not validated
- Delegation Age: Data unavailable
## Neighborhood Assessment (109.207.35.0/24)
- Total Siblings: 35
- Abuse Density: 0.0278 (Low)
- Risk Distribution:
- High Risk: 0
- Medium Risk: 20
- Low Risk: 11
- Notable High-Risk Neighbors:
- 109.207.35.177 (Risk: 70)
- 109.207.35.205 (Risk: 70)
- 109.207.35.206 (Risk: 70)
- 109.207.35.149 (Risk: 45)
## Observation History
12 signal observations recorded. Most recent activity (2026-07-22) indicates:
- Classification: Clean with inherited risk
- Threat observation count: 0
- Ownership changes: 0
- Not persistently malicious
- Subnet abuse density: 0.0278
## Relationships
Two "Same Network" relationships identified, both linking to TRUF network infrastructure.
## Recommended Actions
1. Monitor the subnet 109.207.35.0/24 for elevated activity, particularly from neighbors 109.207.35.177, 109.207.35.205, and 109.207.35.206
2. Block 109.207.35.178 at perimeter firewalls if traffic is not expected from this location
3. Monitor for connection attempts from the subnet during off-hours
4. Verify business legitimacy if traffic from this IP is observed
## SOC Analyst Notes
This IP represents a high-risk classification primarily due to its risk score of 70. However, no direct threat indicators (blacks, known campaigns, active attacks) are present. The primary concern is the subnet-level risk distribution, with 20 medium-risk neighbors in the same /24 block. The route instability flag suggests potential infrastructure changes that may warrant monitoring.
Priority: Medium - Monitor rather than immediate block unless malicious activity is observed.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | AS6700-MNT |
| ASN | AS52026 |
| Network Name | TRUF |
| CIDR Block | 109.207.32.0/20 |
| RIR | ARIN |
| Country | rs |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 443 | https | tcp | — |
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | UBNT-24:5A:4C:C4:ED:AA |
| Valid From | 2019-01-01T00:00:00+00:00 |
| Valid Until | 2038-01-01T00:00:00+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 6940 days |
🛡️ Public Network Snapshot
| Origin ASN | AS52026 |
| Network Prefix | 109.207.35.0/24 |
| Route mapping | Found |
| HSTS | Not detected |
| CSP | Not detected |
| HTTP/2 | Not detected |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Mixed Signals (68%) — 2 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
⚠ TLS certificate claims US but primary geo says RS
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-02 04:20:31 UTC |
| Last Seen | 2026-08-29 04:21:58 UTC |
| Profile Built | 2026-08-29 02:19:34 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 20 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 109.207.35.178
Who owns the IP address 109.207.35.178?
109.207.35.178 is registered to AS6700-MNT. The address falls within the 109.207.32.0/20 network block. Registration is held at ARIN.
Where is 109.207.35.178 located?
Geolocation data places 109.207.35.178 in www.kbcnet.rs. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 109.207.35.178 malicious or safe?
109.207.35.178 currently carries a high risk assessment, meaning indicators associated with malicious or abusive activity have been observed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 109.207.35.178?
Responsive ports observed on 109.207.35.178 include 80, 443, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.