Threat Intelligence Briefing: IP 109.238.140.87/32
Overview:
IP address 109.238.140.87/32 was observed to be associated with a range of activities that may be of interest to network security operations centers (SOC). The intelligence gathered provides a comprehensive profile, including observation history, relationships, and neighborhood data.
Observation History:
- Data Collection Period: The intelligence gathered covers a period from [start date] to [end date].
- Activity Patterns: The IP was noted for engaging in [specific observed activities such as sending/receiving data, connection attempts, etc.] during peak hours. This pattern suggests a potential for [describe any specific threat behavior observed, such as DDoS attempts, malware distribution, etc.].
Relationships:
- Associated Domains: The IP has been linked to multiple domains, including [list of domains]. These domains were observed to host content related to [describe nature of content, e.g., phishing websites, malware distribution, etc.].
- Known Threat Actors: There is evidence suggesting possible affiliations with threat actors known for [specific type of cyber activity, e.g., ransomware, data exfiltration]. This is based on [mention any indicators of compromise or tactics, techniques, and procedures (TTPs) observed].
Neighborhood Data:
- Subnet Analysis: The IP belongs to a subnet with other addresses exhibiting similar behaviors, suggesting a network of related activities. This subnet includes [list of related IPs] that have been observed in conjunction with 109.238.140.87.
- Geolocation: The IP is geolocated to [country/region], which is known for hosting entities involved in [mention any known cybercrime activities prevalent in the region].
Technical Indicators:
- Port Activity: The IP was observed using ports [list of ports], commonly associated with [describe potential malicious use, such as command and control communication, file transfers, etc.].
- Traffic Volume: There was a notable increase in traffic volume during specific time frames, aligning with [describe any correlation with known malicious activity].
Conclusions and Recommendations:
The intelligence gathered on IP 109.238.140.87/32 indicates potential involvement in [summarize potential threat, e.g., cyber espionage, malware distribution]. SOC teams are advised to:
- Monitor network traffic to and from this IP for unusual patterns.
- Implement additional filtering and blocking rules for associated domains.
- Conduct further analysis on related IPs within the same subnet for comprehensive threat mitigation.
This intelligence should be used in conjunction with other threat data to inform defensive strategies and enhance network security posture.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Johan Andersson |
| ASN | AS50821 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | customer-109-238-140-87.stosn.net |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | customer-109-238-140-87.stosn.net |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-dropbear_2020.81 |s????)?^??????[??curve25519-sha256,curve25519-sha256@libssh.org,diffie-he |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 24% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 21% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:03:29 UTC |
| Last Seen | 2026-06-26 18:10:21 UTC |
| Profile Built | 2026-06-22 08:39:55 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 26 |
Full dossier details are available via our API.