Before PEEP
A historical hosting cluster behind the IP later tied to the PEEP toolkit.
Attaxion researchers went back in time with passive DNS and NetFlow data to examine the domains hosted on 206.237.30.232 before it was associated with the PEEP post-exploitation toolkit.
What the investigation uncovered
Download the full report
Get the complete investigation, evidence, methodology, and observables.
One shared IP. A stronger historical trail.
What began as a look at the domains that preceded PEEP on a single IP turned into a multi-year view of coordinated infrastructure management.
Repeated co-location
Two domain families appeared together on two different IP addresses across two hosting environments.
Rapid provisioning
One domain resolved to the host less than an hour after registration, pointing to deliberate setup.
NetFlow rows searched
No flows linked PEEP to the historical pivot IPs within the collection period.
Related domain families
ios-ipa.com, aimiym.com and iosou.com form a related historical infrastructure set.
Shared infrastructure is context, not proof.
The full investigation traces a related set of domains across two hosting environments and years of activity, and shows where the evidence stops. It is a practical look at how to build a historical picture around a malicious IP without overstating attribution.