Threat Intelligence Briefing: IP 173.249.63.227/32
Overview:
The IP address 173.249.63.227/32 was analyzed using multiple intelligence tools to compile a comprehensive profile. The following narrative summarizes the findings, highlighting key observations, relationships, and neighborhood data relevant for a Security Operations Center (SOC) team.
Observation History:
- Domain Associations: The IP address was associated with several domains, primarily used for hosting content and services. Some domains were flagged for hosting phishing content or were linked to suspicious activities.
- Web Hosting: The IP has been utilized for web hosting services, predominantly for legitimate business websites. However, there have been instances where the IP was involved in hosting deceptive websites.
- Traffic Patterns: Traffic analysis indicated spikes in both inbound and outbound connections, consistent with web hosting activities. Anomalous traffic patterns were detected during certain periods, suggesting possible exploitation attempts.
Relationships:
- Associated Domains: The IP address was linked to a series of domains, some of which have been associated with cybercriminal activities, including phishing campaigns. These domains often mimic legitimate business sites to deceive users.
- Organizational Ties: There were connections to hosting services and organizations that have previously been scrutinized for inadequate security measures, potentially leading to vulnerabilities being exploited.
Neighborhood Data:
- Subnet Analysis: The IP resides within a larger network block managed by a commercial hosting provider. Neighboring IPs within the same block have also been involved in hosting dubious content, indicating a possible lax enforcement of content policies by the provider.
- Infrastructure: The infrastructure surrounding the IP suggests a shared hosting environment. This environment has been exploited in the past for distributing malware and conducting denial-of-service attacks.
Threat Analysis:
- Risk Assessment: The IP address poses a moderate threat level due to its association with both legitimate and malicious activities. The presence of phishing domains and unusual traffic spikes necessitates careful monitoring.
- Recommendations: SOC teams should implement continuous monitoring of traffic patterns associated with this IP. Employ threat intelligence feeds to stay updated on any domain changes or new associations. Consider blocking or flagging traffic from this IP if malicious activity is confirmed.
Conclusion:
The analysis of IP 173.249.63.227/32 reveals a mixed-use profile with potential security risks due to its involvement in hosting deceptive content. Vigilance and proactive measures are recommended to mitigate potential threats associated with this IP address.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS51167 |
| Network Name | โ |
| CIDR Block | 173.249.62.0/23 |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vmi3240817.contaboserver.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | mail.energybriefmx.com |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | nginx |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 |
๐ TLS Certificate
| SANs | app.energybriefmx.com |
| Valid From | 2026-06-19T02:44:59+00:00 |
| Valid Until | 2026-09-17T02:44:58+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256RSA |
| Validity Period | 89 days |
| Serial Number | 054F0275D5B691CE97E96E594ACFDDB8E28D |
| Thumbprint | 9AE88C999D446F100B239B73A42371C93FE61EF8 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 3 |
| routing | 32% | 2 | 3 |
| services | 40% | 2 | 5 |
| ownership | 26% | 3 | 4 |
| reputation | 28% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 30% | 12 | 21 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:55 UTC |
| Last Seen | 2026-06-27 02:15:20 UTC |
| Profile Built | 2026-06-27 20:22:33 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 32 |
Full dossier details are available via our API.