IPDebrief

51.79.249.36

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

IPDEBRIEF INTELLIGENCE BRIEFING

Target: 51.79.249.36/32

Date: 2026-08-13

Classification: Moderate Risk

---

Executive Summary

IP 51.79.249.36 is a cloud compute instance hosted by OVH Singapore PTE. LTD (ASN 16276) in the Singapore region. The IP resolved to hostname smtp1.technofection.com and presents as an nginx/1.24.0 web server running on Ubuntu. The address carries a moderate risk score of 50, primarily due to DNSBL listings. No active malicious campaigns, known attacker associations, or spam source indicators were detected. The surrounding /24 subnet (51.79.249.0/24) maintains a clean classification with zero abuse density.

---

Ownership and Infrastructure

The IP resides on OVH's shared cloud infrastructure. The subnet shows one active sibling IP with no detected threats among neighbors.

---

Network Services and DNS

The certificate subject (api.trakomatic.in) differs from the PTR hostname (smtp1.technofection.com), indicating potential service hosting for multiple domains. Email authentication records (SPF, DMARC) are present on the associated domain.

---

Threat Indicators

No threat indicators, active campaigns, or correlated malicious activity were observed.

---

Temporal Analysis

25 signal observations recorded from 2026-08-13. Historical data shows consistent network role classification (cloud infrastructure) and no significant changes in geolocation, DNS, or threat posture over the observation window. The IP has not transitioned to persistently malicious behavior.

---

Control Plane and Routing

---

Recommended Actions

Given the moderate risk score and DNSBL presence, the following actions are recommended for SOC analysts:

1. Monitor: Flag for passive monitoring due to DNSBL listings. No immediate blocking recommended.

2. Investigate: Review outbound connections from api.trakomatic.in and smtp1.technofection.com to verify legitimate email/web service usage.

3. Block Only If: The IP is observed initiating unauthorized connections or exhibiting anomalous traffic patterns inconsistent with web server behavior.

Conclusion: The IP 51.79.249.36 represents a legitimate cloud hosting service with no evidence of malicious activity. The moderate risk score reflects shared hosting environment characteristics and DNSBL listings rather than confirmed threat indicators.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΈπŸ‡¬ Singapore
Regionβ€”
CitySingapore
Timezoneβ€”
Latitude1.28
Longitude103.85

🏒 Ownership & Registration

OrganizationOVH Singapore PTE. LTD
ASNAS16276
Network NameVPS-SGP2
CIDR Block51.79.249.0/24
RIRARIN
CountrySingapore
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRsmtp1.technofection.com
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamessmtp1.technofection.com

πŸ” DNS Hygiene

Hygiene Score80% (Excellent)
SPF2/2 domains
DMARC2/2 domains
FCrDNSVerified
DNSSECValid
CAANot configured
Domains Checked2 domains

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeWeb Server
Network TierTier 3 β€” Basic operator with some routing infrastructure
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpβ€”
443httpstcpβ€”
8080http-alttcpβ€”
Closed Ports22, 25, 3389, 8443 (3 open / 7 scanned)
Servernginx/1.24.0 (Ubuntu)
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
CN=api.trakomatic.in
Issued by CN=YE2, O=Let's Encrypt, C=US
Self-signed: No
SANsapi.trakomatic.in
Valid From2026-08-11T13:31:35+00:00
Valid Until2026-11-09T13:31:34+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha384ECDSA
Validity Period89 days
Serial Number067E960803D3723D3D853680C75D34229718
Thumbprint34D215DB003B415FEC9D0A9B265CDA25A6B2AD7D

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
42%
24
routing
17%
11
services
35%
23
ownership
35%
23
reputation
32%
13
geolocation
35%
23
Overall32%1017
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-08-04 05:43:06 UTC
Last Seen2026-08-13 06:16:30 UTC
Profile Built2026-08-13 06:26:07 UTC
Data FreshnessLive
Signal Types24
Total Observations27
πŸ” 24 signal types Β· 27 observations collected
This report is generated from 24+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.