## IP Intelligence Briefing: 62.60.201.34
Classification: Network Infrastructure / Potential Monitoring Target
Risk Assessment: Low Risk (Score: 25/100)
Analysis Date: 2026-07-29
Executive Summary
IP 62.60.201.34 is a static residential endpoint operated by Hostiran Network within the 62.60.200.0/22 CIDR block. The endpoint shows no active services and maintains a stable network posture. Geographic data presents conflicting indicators between registration records and real-time observations. No active threat indicators detected; however, the IP maintains one DNSBL listing at high severity.
Technical Profile
- ASN: 59441 (Hostiran Network)
- Network: 62.60.201.0/24
- Registration: Ripe NCC (62.60.200.0/22)
- DNS: 62.60.201.34.static.hostiran.name (PTR: Forward confirmed)
- Services: None detected (Firewalled / No Services)
- TLS/HTTP: No certificates, no web services, no HTTP headers detected
- Control Plane: Operator Score 0.2609 (Basic), DNSSEC Valid, Route Stability: Unstable
Geolocation Analysis
Conflicting geographic indicators detected:
- Registration Data: United States (New York, NY)
- Real-time Probes: Tehran, Iran (IR) - Distance: 3,951.6km
- RTT Metrics: Min 180ms, Avg 184.6ms, Max 189ms
- Geo Consensus: False (2 sources disagree)
- Plausibility Assessment: Valid
This discrepancy warrants attention. The substantial distance from the claimed US location suggests either misconfigured geolocation data or the IP may be serving content from Iran while registered in the US.
Threat Intelligence
- Blacklist Status: 1 DNSBL listing out of 8 total lists (High Severity)
- Known Campaigns: None detected
- Threat Feeds: Empty
- Abuse Confidence: Not scored
- Historical Threat Observations: 0
- Malicious Activity: Not persistently malicious
Neighborhood Assessment
- Subnet: 62.60.201.0/24
- Abuse Density: 0%
- Total Siblings: 0
- Threat Siblings: 0
- Risk Distribution: No high/medium/low risk neighbors detected
The /24 subnet shows zero abuse activity, indicating this IP operates in isolation from other potentially malicious endpoints.
Historical Observations (17 Total Signals)
Recent monitoring activity (2026-07-29) reveals:
- Geographic signals showing Tehran, Iran with 3951.6km distance
- No ownership changes detected
- Threat persistence days: 0
- Multiple DNSBL category listings observed with high severity
Entity Relationships
- DNS Associations: 62.60.201.34.static.hostiran.name (3 instances)
- Network Associations: HOSTIRAN (2 instances)
- External Entities: None beyond DNS and network-level associations
Recommended Actions
1. Monitor Geolocation Discrepancy: Investigate why real-time probes indicate Iran while registration shows US
2. Review DNSBL Listing: Examine the single high-severity DNSBL listing to determine cause
3. Route Stability: Investigate unstable route status; may indicate hosting or CDN infrastructure
4. No Immediate Blocking: Low risk score (25) with no active services detected
Conclusion
IP 62.60.201.34 represents a low-risk residential or static endpoint with no active services. The primary intelligence concern is the geographic discrepancy between registration (US) and observation data (Iran), combined with one DNSBL listing. No immediate defensive action required, but continue monitoring for changes in geographic indicators or service activity.
---
*Data sourced from IPDebrief Intelligence Platform. Analysis based on 17 historical observations as of 2026-07-29.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Hostiran Network |
| ASN | AS59441 |
| Network Name | HOSTIRAN |
| CIDR Block | 62.60.200.0/22 |
| RIR | RIPE |
| Country | IR |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 62.60.201.34.static.hostiran.name |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 62.60.201.34.static.hostiran.name |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | 1/2 domains |
| DMARC | 0/2 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
| Domains Checked | 2 domains |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | autoconfig.linux73.centraldnserver.comautodiscover.linux73.centraldnserver.comcpanel.linux73.centraldnserver.comcpcalendars.linux73.centraldnserver.comcpcontacts.linux73.centraldnserver.comipv6.linux73.centraldnserver.comlinux73.centraldnserver.commail.linux73.centraldnserver.comwebdisk.linux73.centraldnserver.comwebmail.linux73.centraldnserver.com |
| Valid From | 2026-06-25T13:29:00+00:00 |
| Valid Until | 2026-09-23T13:28:59+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 89 days |
| Serial Number | 05AE744382715F59A1BE8C16F6C151C96624 |
| Thumbprint | 409B63ED92CF1546CF5BBF1C992186D05EED1DDD |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 4 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-22 07:16:30 UTC |
| Last Seen | 2026-08-13 06:45:13 UTC |
| Profile Built | 2026-08-11 11:50:50 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 24 |
Full dossier details are available via our API.