IPDebrief

62.210.36.194

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING: 62.210.36.194

## Executive Summary

IP 62.210.36.194 is a low-risk cloud infrastructure endpoint operating within the Scaleway provider network (ASN 12876) in Paris, France. The IP demonstrates benign operational characteristics with minimal abuse indicators. However, the DNSBL listing and email-associated hostname warrant monitoring for potential email infrastructure abuse.

---

## Infrastructure Profile

Provider & Classification

Network Role

DNS Configuration

---

## Technical Services

Open Ports

Server Fingerprint

---

## Threat Indicators

Risk Assessment

Threat Campaigns

---

## Neighborhood Analysis (62.210.36.0/24)

---

## Relationship Graph

Key Associations (49 total relationships)

---

## Observation History

Signal Count: 21 observations (most recent: 2026-06-14)

Temporal Trends

Observed Signals

---

## Recommended Actions

Firewall/Security Rules

```bash

# Monitor rather than block - low risk but DNSBL listed

# Recommended: Rate limiting on port 8080

iptables -A INPUT -p tcp --dport 8080 -m limit --limit 10/min -j ACCEPT

iptables -A INPUT -p tcp --dport 8080 -j DROP

```

Monitoring Priorities

1. Track DNSBL listing status (currently 1/8 lists)

2. Monitor for DMARC policy implementation

3. Watch for changes in hostname associations

4. Monitor for unusual traffic patterns on port 8080

Risk Mitigation

---

## Intelligence Conclusion

IP 62.210.36.194 represents a standard cloud hosting endpoint with minimal threat indicators. The DNSBL listing and email-associated hostname suggest this may be part of an email infrastructure deployment. No evidence of malicious activity or campaign association was detected. The subnet demonstrates clean operational characteristics with no neighboring threats. SOC teams may monitor this IP for email-related activity but no immediate blocking action is warranted based on current intelligence.

Classification: LOW RISK - MONITOR

Last Updated: 2026-06-14

Data Confidence: HIGH

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ซ๐Ÿ‡ท France
RegionÎle-de-France
CityParis
TimezoneEurope/Paris
Latitude48.86
Longitude2.35

๐Ÿข Ownership & Registration

OrganizationSCALEWAY
ASNAS12876
Network Nameโ€”
CIDR Blockโ€”
RIRRIPE
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRplanet194.emails.wkmtom.us.com
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnamesplanet194.emails.wkmtom.us.com

๐Ÿ” DNS Hygiene

Hygiene Score60% (Good)
SPFPresent
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeWeb Server
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
443httpstcpโ€”
8080http-alttcpโ€”
Closed Ports22, 25, 3389, 8443 (3 open / 7 scanned)
ServerApache/2.4.59 (Debian)
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
24
routing
13%
11
services
25%
23
ownership
24%
23
reputation
24%
13
geolocation
35%
23
Overall24%1017
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-08 23:18:44 UTC
Last Seen2026-06-27 14:44:23 UTC
Profile Built2026-06-28 08:49:25 UTC
Data FreshnessLive
Signal Types23
Total Observations29
๐Ÿ” 23 signal types ยท 29 observations collected
This report is generated from 23+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.