IPDEBRIEF INTELLIGENCE BRIEFING
Target: 51.79.249.36/32
Date: 2026-08-13
Classification: Moderate Risk
---
Executive Summary
IP 51.79.249.36 is a cloud compute instance hosted by OVH Singapore PTE. LTD (ASN 16276) in the Singapore region. The IP resolved to hostname smtp1.technofection.com and presents as an nginx/1.24.0 web server running on Ubuntu. The address carries a moderate risk score of 50, primarily due to DNSBL listings. No active malicious campaigns, known attacker associations, or spam source indicators were detected. The surrounding /24 subnet (51.79.249.0/24) maintains a clean classification with zero abuse density.
---
Ownership and Infrastructure
- Organization: OVH Singapore PTE. LTD
- Network Block: 51.79.249.0/24 (VPS-SGP2)
- ASN: 16276
- RIR: ARIN
- Classification: CloudCompute, Hosting Provider
The IP resides on OVH's shared cloud infrastructure. The subnet shows one active sibling IP with no detected threats among neighbors.
---
Network Services and DNS
- Open Ports: TCP/80 (HTTP), TCP/443 (HTTPS), TCP/8080 (HTTP-Alt)
- TLS Certificate: Issued by Let's Encrypt for api.trakomatic.in (CN=YE2, O=Let's Encrypt, C=US)
- DNS PTR: smtp1.technofection.com
- Forward Resolution: Single confirmed hostname (smtp1.technofection.com)
- HTTP Status: 404 (Not Found)
The certificate subject (api.trakomatic.in) differs from the PTR hostname (smtp1.technofection.com), indicating potential service hosting for multiple domains. Email authentication records (SPF, DMARC) are present on the associated domain.
---
Threat Indicators
- Risk Score: 50/100 (Moderate)
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Status: 0 direct blacklists, 2 DNSBL listings detected
- Campaign Correlation: None identified
- Threat Persistence: Zero observation count
No threat indicators, active campaigns, or correlated malicious activity were observed.
---
Temporal Analysis
25 signal observations recorded from 2026-08-13. Historical data shows consistent network role classification (cloud infrastructure) and no significant changes in geolocation, DNS, or threat posture over the observation window. The IP has not transitioned to persistently malicious behavior.
---
Control Plane and Routing
- BGP Prefix: 51.79.128.0/17
- Operator Score: 0.2609 (Basic)
- Route Stability: Unstable (isRouteStable: false)
- Route Changes (30d): 0
- DNSSEC: Valid
- RRRP State: Unavailable
---
Recommended Actions
Given the moderate risk score and DNSBL presence, the following actions are recommended for SOC analysts:
1. Monitor: Flag for passive monitoring due to DNSBL listings. No immediate blocking recommended.
2. Investigate: Review outbound connections from api.trakomatic.in and smtp1.technofection.com to verify legitimate email/web service usage.
3. Block Only If: The IP is observed initiating unauthorized connections or exhibiting anomalous traffic patterns inconsistent with web server behavior.
Conclusion: The IP 51.79.249.36 represents a legitimate cloud hosting service with no evidence of malicious activity. The moderate risk score reflects shared hosting environment characteristics and DNSBL listings rather than confirmed threat indicators.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | OVH Singapore PTE. LTD |
| ASN | AS16276 |
| Network Name | VPS-SGP2 |
| CIDR Block | 51.79.249.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | smtp1.technofection.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | smtp1.technofection.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | 2/2 domains |
| DMARC | 2/2 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
| Domains Checked | 2 domains |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 8080 | http-alt | tcp | β |
| Closed Ports | 22, 25, 3389, 8443 (3 open / 7 scanned) | ||
| Server | nginx/1.24.0 (Ubuntu) |
| HTTP Title | β |
π TLS Certificate
| SANs | api.trakomatic.in |
| Valid From | 2026-08-11T13:31:35+00:00 |
| Valid Until | 2026-11-09T13:31:34+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
| Serial Number | 067E960803D3723D3D853680C75D34229718 |
| Thumbprint | 34D215DB003B415FEC9D0A9B265CDA25A6B2AD7D |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 42% | 2 | 4 |
| routing | 17% | 1 | 1 |
| services | 35% | 2 | 3 |
| ownership | 35% | 2 | 3 |
| reputation | 32% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 32% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-08-04 05:43:06 UTC |
| Last Seen | 2026-08-13 06:16:30 UTC |
| Profile Built | 2026-08-13 06:26:07 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 27 |
Full dossier details are available via our API.