Threat Intelligence Briefing: IP 109.207.35.205/32
Summary:
The IP address 109.207.35.205/32 was observed to be associated with a variety of internet activity, primarily linked to hosting services. Analysis of the data collected from multiple sources, including passive DNS, threat intelligence feeds, and network behavior analysis, indicates its use for both legitimate and potentially malicious purposes.
Observation History:
- DNS Records: The IP address has been linked to multiple domain names, some of which were associated with web hosting services. These domains have shown fluctuations in registration patterns, with several domains being registered and de-registered in short intervals.
- Web Hosting Activity: Historical data indicates that the IP has hosted numerous websites over time. Some of these domains were flagged for hosting phishing content or distributing malware.
- Content Analysis: At various points, content served from this IP included suspicious scripts and links, particularly targeting financial institutions and social media platforms.
Relationships:
- Domain Registrations: Several domains associated with this IP address were registered using privacy-focused registrars, making it difficult to identify the registrants. However, patterns suggest potential involvement in hosting phishing and spamming operations.
- Network Connections: Analysis of network traffic logs indicated connections between this IP and known malicious command-and-control (C2) servers, suggesting potential use in botnet activities or as a part of a larger malicious infrastructure.
Neighborhood Data:
- Proximity Analysis: The IP address shares a subnet with other IPs that have been similarly flagged in threat intelligence reports for hosting suspicious or malicious content. This suggests a potential pattern of misuse within this network segment.
- Behavioral Similarities: Other IPs in the same subnet showed similar traffic patterns, such as high volumes of outgoing emails and traffic to known bad domains, indicating a network potentially used for coordinated malicious activities.
Actionable Recommendations:
1. Monitor Traffic: Increase monitoring of traffic to and from this IP address, focusing on patterns that resemble known malicious activities, such as data exfiltration or command-and-control communications.
2. Block and Alert: Implement network rules to block traffic from this IP address, and set up alerts for any attempts to bypass these blocks.
3. Further Analysis: Conduct deeper analysis on any domains hosted by this IP to identify and mitigate any potential threats they may pose.
4. Collaborate with Threat Intelligence Platforms: Share findings with other threat intelligence platforms to help identify and disrupt further malicious activities associated with this IP address.
This briefing provides a comprehensive overview based on observed data and should be used to inform ongoing defensive strategies and threat mitigation efforts.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | AS6700-MNT |
| ASN | AS52026 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | lighttpd/1.4.39 |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 17% | 1 | 1 |
| services | 34% | 2 | 4 |
| ownership | 26% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 27% | 2 | 2 |
| Overall | 27% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:29 UTC |
| Last Seen | 2026-06-25 14:01:38 UTC |
| Profile Built | 2026-06-22 08:46:24 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 20 |
Full dossier details are available via our API.