Skip to content
  Threat research

Before PEEP

A historical hosting cluster behind the IP later tied to the PEEP toolkit.

Attaxion researchers went back in time with passive DNS and NetFlow data to examine the domains hosted on 206.237.30.232 before it was associated with the PEEP post-exploitation toolkit.

What the investigation uncovered

→ Two domain families that moved together across two separate hosting environments
→ A newly surfaced related domain family that serves as a historical pivot
→ A clear line between what the evidence shows and what attribution it can support
Research window
October 2023–September 2026
Data sources
Passive DNS, NetFlow & registration records
Researcher
Mengchen Qu

Download the full report

Get the complete investigation, evidence, methodology, and observables.

 
Key findings

One shared IP. A stronger historical trail.

What began as a look at the domains that preceded PEEP on a single IP turned into a multi-year view of coordinated infrastructure management.

2 IPs

Repeated co-location

Two domain families appeared together on two different IP addresses across two hosting environments.

56 min

Rapid provisioning

One domain resolved to the host less than an hour after registration, pointing to deliberate setup.

99.9M

NetFlow rows searched

No flows linked PEEP to the historical pivot IPs within the collection period.

3

Related domain families

ios-ipa.com, aimiym.com and iosou.com form a related historical infrastructure set.

Why it matters

Shared infrastructure is context, not proof.

The full investigation traces a related set of domains across two hosting environments and years of activity, and shows where the evidence stops. It is a practical look at how to build a historical picture around a malicious IP without overstating attribution.