Threat Intelligence Briefing for IP 31.28.251.169/32
Overview:
The IP address 31.28.251.169/32 was observed to be associated with activities that merit further investigation by SOC teams. The data collected through various intelligence tools provided insights into its behavior, relationships, and neighborhood characteristics.
Observation History:
- Recent Activity: The IP was involved in a series of network connections over the past month, primarily targeting web application endpoints. This activity was characterized by repeated attempts to access specific URLs, suggesting automated scanning or probing behavior.
- Traffic Patterns: Analysis of network traffic indicated a high volume of outbound requests from this IP, particularly during nighttime hours, which is atypical for standard user behavior.
Relationships:
- Associated Domains: The IP was linked to several domains, some of which were flagged for hosting potentially malicious content. These domains were observed to serve as command and control (C2) points for malware campaigns.
- Known Threat Actors: Intelligence sources have associated this IP with a threat actor group known for deploying web-based exploits and data exfiltration techniques.
Neighborhood Data:
- Proximity Analysis: The IP is part of a network segment that includes other addresses with similar malicious indicators. This suggests a coordinated operation possibly involving multiple compromised hosts.
- Infrastructure Overlap: There is notable overlap in the infrastructure used by this IP and other known malicious entities, including shared hosting providers and DNS services.
Actionable Recommendations:
1. Network Monitoring: Increase monitoring of traffic to and from this IP, with a focus on identifying any anomalous patterns or unauthorized access attempts.
2. Access Control: Implement stricter access controls for endpoints that have shown interactions with this IP, particularly during off-hours.
3. Threat Intelligence Sharing: Share findings with relevant threat intelligence communities to aid in the identification of broader patterns and potential defenses against the associated threat actor group.
4. Incident Response Preparedness: Ensure that incident response plans are up-to-date and capable of addressing potential breaches originating from interactions with this IP.
This intelligence briefing aims to provide SOC analysts with the necessary information to assess the risk posed by IP 31.28.251.169/32 and to take appropriate defensive measures.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Lancom Admins Group |
| ASN | AS35816 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | undefined.sevstar.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | undefined.sevstar.net |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | Web server |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 32% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 11% | 1 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 21% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 20% | 9 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:15 UTC |
| Last Seen | 2026-06-23 09:59:35 UTC |
| Profile Built | 2026-06-23 10:22:50 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.