IPDebrief

109.207.35.178

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 109.207.35.178/32

## Executive Summary

IP address 109.207.35.178 is classified as High Risk (Risk Score: 70). The address is associated with TRUF network infrastructure in Serbia and shows no active open services. While the IP itself shows no direct threat indicators, it resides within a subnet containing 20 medium-risk neighbors, suggesting potential lateral threat activity.

## Network Profile

## Threat Indicators

## Control Plane Analysis

## Neighborhood Assessment (109.207.35.0/24)

- High Risk: 0

- Medium Risk: 20

- Low Risk: 11

- 109.207.35.177 (Risk: 70)

- 109.207.35.205 (Risk: 70)

- 109.207.35.206 (Risk: 70)

- 109.207.35.149 (Risk: 45)

## Observation History

12 signal observations recorded. Most recent activity (2026-07-22) indicates:

## Relationships

Two "Same Network" relationships identified, both linking to TRUF network infrastructure.

## Recommended Actions

1. Monitor the subnet 109.207.35.0/24 for elevated activity, particularly from neighbors 109.207.35.177, 109.207.35.205, and 109.207.35.206

2. Block 109.207.35.178 at perimeter firewalls if traffic is not expected from this location

3. Monitor for connection attempts from the subnet during off-hours

4. Verify business legitimacy if traffic from this IP is observed

## SOC Analyst Notes

This IP represents a high-risk classification primarily due to its risk score of 70. However, no direct threat indicators (blacks, known campaigns, active attacks) are present. The primary concern is the subnet-level risk distribution, with 20 medium-risk neighbors in the same /24 block. The route instability flag suggests potential infrastructure changes that may warrant monitoring.

Priority: Medium - Monitor rather than immediate block unless malicious activity is observed.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇷🇸 RS
Region—
Citywww.kbcnet.rs
Timezone—
Latitude44.82
Longitude20.45

🏢 Ownership & Registration

OrganizationAS6700-MNT
ASNAS52026
Network NameTRUF
CIDR Block109.207.32.0/20
RIRARIN
Countryrs
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)

🔐 DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierUnknown — Insufficient routing data to classify
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
80httptcp—
443httpstcp—
22sshtcpBanner detected
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
ServerWeb server detected
HTTP Title—

🔐 TLS Certificate

A self-signed certificate was detected. This is common for development servers, internal services, or IoT devices.
⚠️
E=support@ubnt.com, CN=UBNT-24:5A:4C:C4:ED:AA, OU=Technical Support, O=Ubiquiti Networks Inc., L=San Jose, S=CA, C=US
Issued by E=support@ubnt.com, CN=UBNT-24:5A:4C:C4:ED:AA, OU=Technical Support, O=Ubiquiti Networks Inc., L=San Jose, S=CA, C=US
Self-signed: Yes
SANsUBNT-24:5A:4C:C4:ED:AA
Valid From2019-01-01T00:00:00+00:00
Valid Until2038-01-01T00:00:00+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period6940 days

🛡️ Public Network Snapshot

Origin ASNAS52026
Network Prefix109.207.35.0/24
Route mappingFound
HSTSNot detected
CSPNot detected
HTTP/2Not detected

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
0%
00
reputation
0%
00
geolocation
0%
00
Overall12%33
Coverage: 3/6 dimensions · Data sufficiency: partial
Data CoherenceMixed Signals (68%) — 2 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Geo sources disagree on country: US, RS
⚠ TLS certificate claims US but primary geo says RS

📅 Observation Timeline 🔄 Live

First Seen2026-07-02 04:20:31 UTC
Last Seen2026-08-29 04:21:58 UTC
Profile Built2026-08-29 02:19:34 UTC
Data FreshnessLive
Signal Types17
Total Observations20
🔍 17 signal types · 20 observations collected
This report is generated from 17+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 109.207.35.178

Who owns the IP address 109.207.35.178?

109.207.35.178 is registered to AS6700-MNT. The address falls within the 109.207.32.0/20 network block. Registration is held at ARIN.

Where is 109.207.35.178 located?

Geolocation data places 109.207.35.178 in www.kbcnet.rs. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 109.207.35.178 malicious or safe?

109.207.35.178 currently carries a high risk assessment, meaning indicators associated with malicious or abusive activity have been observed. This assessment is generated from continuously collected signals and can change over time.

What ports are open on 109.207.35.178?

Responsive ports observed on 109.207.35.178 include 80, 443, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.

🏘️ Related IP Addresses

Nearby addresses in 109.207.32.0/20

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.