Threat Intelligence Briefing: IP 5.175.206.114/32
Summary:
The IP address 5.175.206.114/32 was analyzed to determine its associated risk and operational characteristics. The findings are based on observed data from various threat intelligence tools and sources.
Observation History:
- Activity Pattern: The IP has shown consistent traffic patterns typical of a residential proxy, suggesting possible use in anonymizing activities or masking the origin of traffic.
- Geolocation Data: The IP is geographically associated with Vietnam, indicating that it may be used by individuals or entities within or targeting this region.
Relationships:
- Known Associations: The IP was linked to a range of peer IPs that are commonly used for residential proxy services. These relationships suggest potential use in activities requiring anonymity.
- Malware Connections: Historical data indicates that the IP was involved in traffic associated with known malware families, including adware and tracking scripts. However, no recent malicious activity was detected.
Neighborhood Data:
- Network Environment: The IP resides within a network segment known for hosting residential proxies. This environment is characterized by shared IP addresses among multiple users, complicating attribution.
- Risk Level: The surrounding network is flagged for moderate risk due to its history of hosting anonymized traffic and occasional association with malware distribution.
Actionable Insights:
- Monitoring: Continuous monitoring of traffic patterns associated with this IP is recommended to detect any resurgence of malicious activity.
- Anomaly Detection: Implement anomaly detection rules to flag unusual traffic patterns that could indicate misuse of the IP for malicious purposes.
- Threat Hunting: Consider proactive threat hunting to identify any potential exploitation of this IP within the network.
Conclusion:
While no immediate threat was observed from IP 5.175.206.114/32, its historical associations and network environment warrant cautious monitoring. The IP's use as a residential proxy suggests potential for both benign and malicious use, necessitating vigilance in network security operations.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | GHOSTNET-MNT |
| ASN | AS203516 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 5-175-206-114.altunhost.com |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 5-175-206-114.altunhost.com |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 3389 | rdp | tcp | โ |
| Closed Ports | 22, 25, 80, 443, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 5 |
| routing | 13% | 1 | 1 |
| services | 20% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 26% | 1 | 4 |
| geolocation | 37% | 2 | 3 |
| Overall | 25% | 10 | 19 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:24 UTC |
| Last Seen | 2026-06-23 15:21:29 UTC |
| Profile Built | 2026-06-23 15:24:10 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.