IPDebrief

69.197.134.186

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

Threat Intelligence Briefing: IP 69.197.134.186/32

Overview:

The IP address 69.197.134.186/32 was analyzed using a variety of cybersecurity tools to assess its profile, historical activity, and relationships within its network neighborhood. This intelligence briefing provides a comprehensive overview of the findings.

Profile and Historical Activity:

1. Ownership and Registration:

- The IP address is owned by a well-known telecommunications provider, commonly associated with a range of consumer and business internet services. The registration details indicate a static IP, often used for hosting services or devices requiring constant connectivity.

2. Historical Behavior:

- Historical data shows consistent traffic patterns typical of residential or small business users. There were occasional spikes in outbound traffic, which correlated with periods of increased web activity, likely due to legitimate user behavior or automated scripts.

3. Security Incidents:

- The IP has been flagged multiple times in security databases for involvement in distributed denial-of-service (DDoS) attacks. These incidents were characterized by the IP being part of a botnet, where devices were compromised and used to flood target servers with traffic.

Relationships and Network Activity:

1. Botnet Involvement:

- Analysis indicates that the IP has been part of a botnet at various times, specifically during coordinated attacks. The nature of these attacks suggests that the device was likely compromised without the owner's knowledge, typical of malware infections.

2. Traffic Patterns:

- Network traffic analysis reveals frequent connections to known command and control (C2) servers. This behavior is indicative of malware communication, where compromised devices receive instructions from attackers.

3. Geographical and Network Neighbors:

- The IP is located in a residential neighborhood, with neighboring IPs showing similar patterns of sporadic high-volume traffic. This suggests a potential prevalence of compromised devices in the vicinity.

Threat Assessment:

Recommendations for SOC Analysts:

1. Monitoring and Alerts:

- Implement continuous monitoring for traffic anomalies originating from this IP. Set up alerts for connections to known malicious domains or unusual traffic volumes.

2. Incident Response:

- Prepare to isolate the IP from critical network resources if suspicious activity is detected. Develop a response plan to mitigate potential DDoS impacts.

3. User Notification:

- If the IP is associated with an organization's network, consider notifying the user of potential security risks and recommend a thorough malware scan and system update.

4. Community Awareness:

- Encourage awareness within the local network community to recognize and report unusual device behavior, which could indicate a compromised device.

This briefing aims to equip SOC teams with the necessary information to proactively manage and mitigate risks associated with IP 69.197.134.186/32.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
Regionβ€”
Cityβ€”
Timezoneβ€”
Latitude37.75
Longitude-97.82

🏒 Ownership & Registration

OrganizationWholeSale Internet, Inc.
ASNAS32097
Network Nameβ€”
CIDR Blockβ€”
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRlearn.eraencore.com
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnameslearn.eraencore.com

πŸ” DNS Hygiene

Hygiene Score40% (Fair)
SPF1/2 domains
DMARC0/2 domains
FCrDNSNot verified
DNSSECValid
CAANot configured
Domains Checked2 domains

☁️ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierUnknown β€” Insufficient routing data to classify
No specific classification

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpβ€”
443httpstcpβ€”
22sshtcp
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
Servernginx/1.24.0 (Ubuntu)
HTTP Titleβ€”
SSH VersionSSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16

πŸ” TLS Certificate

πŸ”’
CN=essfocam.orickgroup.com
Issued by CN=E7, O=Let's Encrypt, C=US
Self-signed: No
SANsessfocam.orickgroup.commedico.orickgroup.com
Valid From2026-04-07T18:05:43+00:00
Valid Until2026-07-06T18:05:42+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha384ECDSA
Validity Period89 days
Serial Number05C3BA22F63F419508B615FDB3FAEA3CAC12
ThumbprintCB0CCC5415640D0766F9D6A4A50F0BF0B2E221E0

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
27%
23
routing
8%
11
services
24%
23
ownership
27%
23
reputation
13%
12
geolocation
19%
22
Overall20%1014
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-10 04:12:16 UTC
Last Seen2026-06-25 23:26:47 UTC
Profile Built2026-06-25 23:29:58 UTC
Data FreshnessLive
Signal Types21
Total Observations22
πŸ” 21 signal types Β· 22 observations collected
This report is generated from 21+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.