IP Address OSINT

 

An IP address is a unique numerical label dynamically or statically assigned to a network interface by an administrator or automated system. It serves as the foundational identifier enabling communication between devices across IP-based networks using the Internet Protocol suite.

 
An IP address serves two major functions:

  • Network Interface Identification: Distinguishing individual hosts or interfaces on a network.
  • Location Addressing: Facilitating routing of data packets across local and wide-area networks, including the public internet.


In the domain of digital forensics and OSINT, IP addresses constitute high-probative-value artifacts. Whether IPv4 (32-bit) or IPv6 (128-bit), these identifiers function as critical pivot points in attribution workflows. They enable investigators to correlate network activity, email metadata, memory artifacts, server logs, and geolocation data, often revealing the originating device, infrastructure, or user behavior during online operations.


The context in which an IP address surfaces as an investigative target varies significantly. Law enforcement entities frequently obtain offender IPs through legal process (e.g., subpoenas or court orders directed at Internet Service Providers). OSINT practitioners and online researchers, by contrast, routinely discover and enrich IPs during passive and semi-passive reconnaissance — via domain enumeration, WHOIS queries, certificate transparency logs, server header analysis, or open-source threat intelligence platforms.It is essential to note the distinction between domains and hosting infrastructure: a single domain typically resolves to one primary IP at any given time, yet a single IP address can host multiple domains (shared hosting environments, virtual hosts, or CDN configurations). This many-to-one relationship underscores the need for careful validation and enrichment during attribution.


ViewDNS Reverse IP

ViewDNS Reverse IP is a high-value OSINT utility that performs a reverse IP lookup (also known as a reverse DNS or virtual host enumeration) on a target domain or IP address. It rapidly enumerates and surfaces all other domains and hostnames sharing the same IP address or server infrastructure.


Key OSINT Applications

  • Shared Hosting Enumeration: Identifies additional websites hosted on the same server or IP, revealing potential infrastructure relationships.
  • Phishing & Threat Actor Tracking: Uncovers other malicious or suspicious domains co-located with a known phishing, C2, or scam site — a common tactic used by threat actors on compromised or bulletproof hosting.
  • Infrastructure Mapping: Exposes the full digital footprint of a target organization or actor operating across multiple domains on shared resources.
  • Pivoting: Serves as an efficient pivot point for expanding reconnaissance from a single observed domain or IP to a broader network of associated assets.


This tool is particularly effective in environments where multiple virtual hosts are served from a single IP (common in shared hosting, VPS, or cloud deployments). It provides investigators with immediate visibility into co-hosted assets that may not be easily discoverable through forward DNS queries alone.


In attribution workflows, ViewDNS Reverse IP enables rapid correlation of seemingly disparate domains, accelerating the identification of campaign infrastructure, sinkholing opportunities, or defensive takedown research.


ViewDNS IP Location

ViewDNS IP Location is a precise OSINT geolocation utility that resolves a supplied IPv4 or IPv6 address to its associated physical and administrative location data. Leveraging aggregated BGP, registry, and geodatabase intelligence, it extracts key attribution elements, including city, region, country, postal code, coordinates, and timezone information. Example Output for 151.139.128.10 is given below:


IP Location Results for 151.139.128.10
==============

City:         Dallas
Zip Code:     75201
Region Code:  TX
Region Name:  Texas
Country Code: US
Country Name: United States
Latitude:     32.7889
Longitude:    -96.8021
GMT Offset:   
DST Offset


Operational Value in OSINT & Investigations

  • Rapid Attribution: Transforms a raw IP address into actionable geographic intelligence, supporting device/user localization during incident response, threat hunting, or open-source investigations.
  • Corroboration & Enrichment: Serves as a critical pivot for cross-referencing with other artifacts (e.g., WHOIS data, Reverse IP results, server logs, or historical resolutions).
  • Campaign Mapping: Enables visualization of attacker infrastructure, victim distribution, or C2 server placement across jurisdictions.
  • Evidentiary Support: Provides probative geolocation context in digital forensics, subpoena preparation, or intelligence reporting.


This tool excels in the initial stages of IP-driven reconnaissance by delivering fast, structured geointelligence. When combined with ViewDNS Reverse IP and other enumeration modules, it significantly accelerates the construction of a comprehensive target infrastructure profile.


Note: Accuracy is generally high for residential/commercial ranges but can vary for VPNs, proxies, hosting providers, or anycast infrastructure — always validate with multiple sources.


ViewDNS Port Scan

ViewDNS Port Scanner is a lightweight, web-based reconnaissance tool that performs a targeted SYN-style scan of a selected IP address or hostname against a curated list of high-value common ports. It rapidly determines the open/closed status of services exposed to the public internet, providing immediate insight into the target’s attack surface and active services. Ports scanned include: 21 (FTP), 22 (SSH), 23 (Telnet), 25 (SMTP), 80 (HTTP), 110 (POP3), 139 (NetBIOS), 143 (IMAP), 445 (SMB), 1433 (MSSQL), 1521 (Oracle), 3306 (MySQL), 3389 (RDP), and additional common web ports such as 443 (HTTPS) as evidenced in live results.


A search of 151.139.128.10 was conducted and Ports 80 (HTTP) and 443 (HTTPS) were reported as open to external connections, as at the time of writing, indicating active web services on the target.



OSINT & Investigative Value

  • Service Enumeration: Quickly verifies whether critical services (web, mail, remote access, database, file sharing) are exposed and potentially reachable from the internet.
  • Attack Surface Mapping: Identifies internet-facing services that may represent points of interest for further vulnerability assessment, misconfiguration discovery, or defensive analysis.
  • Infrastructure Validation: Confirms the operational status of suspected C2 servers, phishing hosts, or compromised assets.
  • Pivoting Support: Serves as an efficient filter to prioritize deeper enumeration (e.g., version detection, banner grabbing, or web application fingerprinting) on confirmed open ports.


In a mature OSINT workflow, the ViewDNS Port Scanner functions as a fast triage instrument — ideal for initial reconnaissance before deploying more comprehensive tools such as Nmap. It enables analysts to efficiently validate hypotheses about exposed services while maintaining a low-profile, browser-based approach.


Limitation Note: As a web-based utility, it offers limited port coverage and lacks advanced stealth or customization options compared to dedicated scanning platforms.


ViewDNS IP Whois

ViewDNS IP Whois is a comprehensive OSINT intelligence module that retrieves authoritative registration and ownership data for both IP addresses (IPv4/IPv6) and domain names. It queries regional internet registries (RIRs) such as ARIN, RIPE, APNIC, LACNIC, and AFRINIC, along with domain registrars, to surface ownership, contact, and administrative details.


Primary Capabilities

  • IP Block Ownership: Identifies the allocating organization, ISP, hosting provider, or network operator responsible for the IP address or netblock.
  • Registration Metadata: Extracts organization name, address, abuse contact information, registration dates, and ASN associations.
  • Domain Availability Check: Determines whether a domain name is registered or available for registration.
  • Historical Context: Provides insight into the responsible entity behind an IP infrastructure.


Investigative Value in OSINT:

  • Attribution & Ownership Mapping: Establishes the legal and operational entity behind a target IP, enabling rapid identification of hosting providers, bulletproof hosts, or upstream networks.
  • Abuse Reporting & Takedowns: Supplies verified abuse contact points (e.g., abuse@ mailboxes) critical for coordinated incident response and mitigation.
  • Infrastructure Intelligence: Reveals relationships between IPs, netblocks, and organizations—a foundational step in mapping threat actor hosting patterns.
  • Due Diligence: Validates whether an IP belongs to a legitimate organization or a suspicious provider.


Example Result for 151.139.128.10 shows the IP address belongs to the RIPE Network Coordination Centre (or its downstream customer), returning full public registration details, including organization information, net range, and contact records.

In advanced workflows, ViewDNS IP Whois serves as an essential early-stage reconnaissance tool. It delivers structured, actionable intelligence that feeds directly into reverse IP analysis, geolocation correlation, and broader infrastructure profiling. When used in tandem with other ViewDNS modules, it significantly strengthens attribution accuracy and accelerates decision-making in both defensive and offensive OSINT operations.


ViewDNS Traceroute

ViewDNS Traceroute is a web-based network diagnostic and reconnaissance utility that maps the complete path data packets take from the ViewDNS infrastructure to a target domain name or IP address. It performs a classic IP Time-To-Live (TTL) based traceroute, revealing each intermediate router, gateway, and hop along the routeThis can identify IP addresses of servers that were contacted while you tried to establish communication with the target's address. These will occasionally identify associated networks, routers, and servers. Additional IP addresses can be later searched for further details. The numbers after the IP addresses indicate the number of milliseconds that each "hop" took.


Key Intelligence Outputs

  • Sequential list of IP addresses encountered at each hop.
  • Round-Trip Time (RTT) latency measurements in milliseconds for each hop.
  • Identification of upstream providers, backbone routers, peering points, and edge devices.


OSINT & Investigative Applications

  • Path Analysis & Infrastructure Mapping: Exposes the network topology and routing infrastructure between the probe source and the target, often revealing hosting providers, transit networks, and geographic routing patterns.
  • Pivot Point Discovery: Identifies additional IP addresses and autonomous systems (ASNs) that can be further enriched using Reverse IP, IP Whois, Geolocation, or Port Scanning modules.
  • Anomaly Detection: Helps detect unusual routing, potential traffic interception points, or load-balanced environments (anycast).
  • Network Relationship Building: Correlates intermediary hops with known infrastructure to better understand the target’s hosting ecosystem and resilience.


The numbers following each IP address represent the latency (in milliseconds) for that specific hop. These timing values can assist in identifying network congestion, long-haul links, or performance characteristics of the target’s connectivity.


In mature OSINT workflows, ViewDNS Traceroute functions as a lightweight yet valuable reconnaissance layer. While it lacks the depth and stealth of tools such as mtr or advanced Nmap traceroute options, its browser-accessible nature makes it an excellent rapid triage instrument for quickly expanding the scope of an IP or domain investigation and uncovering associated network infrastructure.


ViewDNS Reverse DNS

ViewDNS Reverse DNS is a precise OSINT utility that queries the PTR (Pointer) record for a given IP address. It resolves the IP back to its associated hostname, revealing the official or configured server/host name assigned by the network owner


Core Function

Performs a reverse DNS lookup on an IPv4 or IPv6 address to retrieve the canonical hostname (if one exists). This is the inverse of a standard forward DNS (A/AAAA) record lookup.


OSINT & Investigative Value

  • Host Identification: Frequently discloses the actual server name, CDN edge node, load balancer, or infrastructure hostname — often more revealing than the forward domain.
  • Infrastructure Fingerprinting: Helps map and attribute hosting environments, content delivery networks (CDNs), cloud providers, or enterprise systems.
  • Correlation & Enrichment: Serves as a strong pivot point when combined with IP Whois, Reverse IP, Port Scanning, and Geolocation data.
  • Validation: Confirms whether an IP belongs to a specific service or platform (e.g., web accelerators, mail servers, or monitoring nodes).


The example result for 151.139.128.10 is shown below:


Reverse DNS results for 151.139.128.10
10.128.139.151.in-addr.arpa domain name pointer map3.hwcdn.net.

In this case, the IP resolves to map3.hwcdn.net, indicating an association with a Highwinds CDN (now part of StackPath) infrastructure.


 Bing IP Search (Manual Reverse IP Enumeration

Once an IP address associated with a target has been identified, a high-yield passive reconnaissance technique involves leveraging Bing’s web indexing to enumerate other websites hosted on the same server or IP address. Perform a direct IP search on Bing using the target IP as the query term. This exploits Bing’s ability to index and surface hosts by IP address, effectively revealing co-hosted domains and virtual hosts.


Search Syntax:

https://www.bing.com/search?q=151.139.128.10

(or simply enter the raw IP address into Bing’s search bar).


Intelligence Value & Limitations:

  • High-Value Scenarios: When the target is hosted on a dedicated or semi-dedicated server (e.g., an individual VPS, colocation, or private web server), this method can expose the full portfolio of websites controlled by the same user or organization—a powerful pivot for attribution.
  • Low-Value Scenarios: On large shared hosting platforms (e.g., GoDaddy, Bluehost, or major cloud providers), results are often noisy and provide limited actionable intelligence, as they simply list unrelated sites sharing the same physical or virtual server.
  • Operational Context: This technique works reliably on Bing but generally yields poor or no results on Google due to differences in indexing behavior.

Strategic Application in OSINT:

  • Rapid discovery of additional domains under the same administrator or infrastructure owner.
  • Identification of personal or corporate website portfolios.
  • Detection of related business entities, side projects, or secondary assets.
  • Cross-verification with ViewDNS Reverse IP for higher accuracy and completeness.


Pro Tip: Always document the search URL and timestamp the results. Combine this method with ViewDNS Reverse IP, IP Whois, and Reverse DNS for robust multi-source validation. This Bing-based approach remains a valuable, zero-footprint OSINT tactic despite its dependency on search engine behavior.


IP Location

IPLocation is a robust, free OSINT geolocation platform that aggregates and cross-references data from up to eight distinct IP intelligence sources in a single query. It delivers one of the most comprehensive free IP address lookup experiences available, providing enriched attribution details beyond standard single-source databases.


Key Capabilities

  • Unlimited free searches with no registration required.
  • Multi-vendor data fusion for improved accuracy and redundancy checking.
  • Detailed output including country, region, city, ISP, organization name, latitude/longitude, and additional metadata.


Intelligence Interpretation & Limitations:

  • Geographic Resolution: While GPS-level coordinates are often returned, they typically reflect the ISP or data center location rather than the precise end-user position. Country, region, and city-level data are generally reliable.
  • Organization Attribution: When an organization name appears, it usually indicates the IP is directly assigned to that entity (e.g., corporate network or hosting provider). Identification of a major ISP, however, only confirms ownership of the address block—not the end user.
  • Operational Use Cases:
    • Rapid determination of whether a target IP belongs to a business, educational institution, or public Wi-Fi provider.
    • Quick identification of VPNs, proxies, or anonymization services.
    • Validation of hosting provider vs. residential/consumer connections.
    • Supporting evidence in user behavior profiling and infrastructure mapping.


IPLocation stands out as a high-utility free resource due to its multi-source aggregation, which helps mitigate inaccuracies common in single-database lookups. In practice, it serves as an excellent corroborative tool when used alongside ViewDNS IP Location, MaxMind, or commercial threat intelligence platforms.


For best results in serious investigations, always cross-verify geolocation data across multiple services, as IP-to-location mapping can be impacted by anycast routing, CDN distribution, and VPN usage.


ThatsThem

Unlike traditional IP lookup services that rely primarily on public registration records, geolocation databases, and network information, ThatsThem is a people-search service that aggregates data from a variety of public records and commercially available data sources. In some cases, it may associate IP addresses with individuals or organizations when such information exists in its database. Because its data depends on previously collected records, search results can vary widely and may be more useful for IP addresses that have been consistently associated with a particular individual or organization over time than for frequently changing residential IP addresses.


I Know What You Download 

This resource might be the most personal of all invasive websites. This service monitors online torrents (ways to download large files which often violate copyright laws) and discloses the files associated with any collected IP addresses. Searching my own IP address revealed the following.

 



It identifies that the target IP address was downloading the above movies on May 6 and May 8, 2022. Clicking on the movie title presents every IP address captured that also downloaded the same file. Again, this will work best with IP addresses that rarely change, such as a business, organization, or public Wi-Fi network. On one occasion, this revealed an employee that was downloading enormous amounts of pornography on his employer's network. He should have used a VPN, which would have masked his online activity. In order to see the power of this type of service, try searching a known VPN address such as an address provided by Private Internet Access (PIA) 173.244.48.163.The direct URL query follows:


https://iknowwhatyoudownload.com/en/peer/?ip=105.112.160.123


Exonerator

If you cannot locate any valuable information about your target IP address using the previous techniques,  it is possible that the address was part of the Tor network and there is no relevant data to be located.


The ExoneraTor service maintains a database of IP addresses that have been part of the Tor network.  It answers the question whether there was a Tor relay running on a given IP address on a given date. While a date is required, you could provide the current date if your target time frame is unknown. Most IP addresses are typically always or never a part of the Tor network.


Shodan

Shodan is a search engine that lets you find specific computers (routers, servers, etc.) using a variety of filters. General search engines, such as Google and Bing, are great for finding websites; however, they do not search for computers or devices. Shodan indexes "banners", which are metadata that a device sends back to a client. This can be information about the server software, what options the service supports, or a welcome message. Devices that are commonly identified through Shodan include servers, routers, online storage devices, surveillance cameras, webcams, and VOIP systems. Network security professionals use this site to identify vulnerabilities on their systems. Criminals use it to illegally access networks and alter devices. In order to take advantage of Shodan's full search capabilities, you must create a free account. Only a name and email address is required. The following shows the result of searching the IP address 70.39.81.131




ZoomEye

Developed by Chinese security company Knownsec Inc. This Shodan competitor provides a similar service, often with unique results.


IP2Location

IP2Location™ is a non-intrusive IP location lookup technology that retrieves geolocation information with no explicit permission required from users. A search of my IP address 105.112.160.93 reveals the following information.

{ "response": "OK", "country_code": "NG", "country_name": "Nigeria", "region_name": "Lagos", "city_name": "Lagos", "latitude": 6.45306, "longitude": 3.39583, "zip_code": "102103", "time_zone": "+01:00", "isp": "Airtel Networks Limited", "domain": "airtel.com", "net_speed": "DSL", "idd_code": "234", "area_code": "0704", "weather_station_code": "NIXX0012", "weather_station_name": "Lagos", "mcc": "621", "mnc": "20", "mobile_brand": "Airtel", "elevation": 9, "usage_type": "ISP\/MOB", "address_type": "Unicast", "category": "IAB19-18", "category_name": "Internet Technology", "geotargeting": { "metro": "-" }, "continent": { "name": "Africa", "code": "AF", "hemisphere": [ "north", "east" ], "translations": { "zh-cn": "\u975e\u6d32" } }, "country": { "name": "Nigeria", "alpha3_code": "NGA", "numeric_code": "566", "demonym": "Nigerians", "flag": "https:\/\/cdn.ip2location.com\/assets\/img\/flags\/ng.png", "capital": "Abuja", "total_area": "923768", "population": "206139589", "currency": { "code": "NGN", "name": "Nigerian Naira", "symbol": "\u20a6" }, "language": { "code": "EN", "name": "English" }, "idd_code": "234", "tld": "ng", "is_eu": false, "translations": { "zh-cn": "\u5c3c\u65e5\u5229\u4e9a" } }, "country_groupings": [ { "acronym": "African Union", "name": "African Union" }, { "acronym": "Commonwealth of Nations", "name": "Commonwealth of Nations" } ], "region": { "name": "Lagos", "code": "NG-LA", "translations": { "zh-cn": "\u62c9\u5404\u65af" } }, "city": { "name": "Lagos", "translations": [] }, "time_zone_info": { "olson": "Africa\/Lagos", "current_time": "2022-05-14T21:29:24+01:00", "gmt_offset": 3600, "is_dst": "no", "sunrise": "06:30", "sunset": "18:55" }, "credits_consumed": 35 }


IP2Location email tracer provides a large text box into which an entire email header can be copied for analysis. The response includes the IP address and location of the sender; interactive map identifying the originating location; internet service provider; and links to additional information from an IP search. Anyone wanting more information from an email threat should start here.

 

Obtaining the IP Address of a Target

 You may wish to get the IP address of your target from their ISP. This IP address could be used to confirm the approximate location of the suspect, offer law enforcement information for a court order or to determine if multiple email addresses belong to the same suspect.


IP Logger

This specific technique involves some trickery and the need to contact the target from a covert account. For this demonstration, assume your target has a Facebook page that he checks regularly. You can send him a private message that includes "bait" in the form of an online link. A detailed set of instructions should explain the processes. The main website presents several options, but only the "URL & Image Shortener" service will be explained.


Link

You can generate a URL which will redirect to any website that you provide. IP Logger will save the IP address of each user who clicked the link. In the box provided, enter any address that you want the target to see when clicking on a link. This could be something generic such as twitter.com. After submitting, you will receive a series of links. This page also serves as the log of visitors, and I recommend documenting it. In an example, I received the following link at the beginning of this list.


https://iplogger.org/2NB947


Clicking this link or typing it into a browser forwards the target to twitter.com. This action collects his or her IP address, operating system, and browser details. These details, along with the date and time of capture, can be viewed at the link generated previously. A URL shortening service such as Bitly (bit.ly) would make the link look less suspicious. 


Image

You can provide a digital image to this service, and it will create a tracker out of it for placement onto a website, forum, or email message. I provided an image that is present on this blog at


https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg3ERl-uUHz2z6cePizTDip0E6KlH4DV5Wvc6yLIHqHUgDcqAnCZN9G8-tRekJFzl5f_hiQtENu5jx885uZDySbb2Cy24CEc5YCEM6P-Q18ZmsNT7XilRjofCVTKqogU4bJfaINL4nHn9NgECloPIXzZQOC_uTy92TlHs943dxsS1cKbmDaUxpcnkOD/s781/osintemail.JPG.jpg


This presented a page similar to the previous example. I was provided the following link.


https://iplogger.org/3njw44


This link forwards to the image that I provided. During this process, the IP address, operating system, and browser details are collected and stored on the page that stored the links.


Canary Tokens

Canarytokens is a tool that helps you discover you've been breached by having attackers announce. It is a file, URL, API key, or other resource (containing a tracker) that is monitored for access. Once the resource has been accessed, an alert is triggered notifying the object owner of said access.


Ultimately, you should familiarize yourself with all options and choose which works best for you.


Always remember that technologies such as VPNs, Tor, and other forms of IP masking may create inaccurate results. Always use caution when sending these types of trackers, and make sure you are not violating any laws or internal policies. Due to the heavy usage of VPNs within the communities in which I investigate, I find these services slowly becoming less useful.


Get Notify

There is a glaring problem with all of these public IP logging services. They are well-known and may be blocked by email providers. Gmail typically blocks any domains associated with either IP Logger or Canary Tokens. A tech-savvy target may recognize these tactics which could jeopardize your investigation. For these reasons, I prefer GetNotify.


GetNotify tracks the opening of email messages and presents the connection information of the target. This service is completely free and does not require Gmail as your email provider. You will need to create an account through the Get Notify website and you will be limited to five email messages per day. After you have registered the email address you will be using, you can send emails from that account as usual. However, you will need to add ".getnotify.com" after each email recipient. Instead of sending an email message to the valid account of  
meetjosephmoronwi@programmer.net, you would send the message to a modified email address of meetjosephmoronwi@programmer.net.getnotify.com. This will force the email message to go through Get Notify's servers and route the message to the valid address. When your target reads the email message, Get Notify will track the user's IP address, geographical location, and notify you whether your message was viewed for a length of time or deleted right away.

Get Notify works by adding a small invisible tracking image in your outgoing emails. When your email recipient opens your message, this image gets downloaded from a GetNotify server. GetNotify will know exactly when your sent email was opened and it notifies you through an email that your sent message was read by the recipient. You can also view log files within your online account. The tracking image inserted by Get Notify is invisible to the recipient. Optionally, you can specify your own images to be used as tracking images by going to the preferences section after signing in to GetNotify.com. Your recipient will not see ".getnotify.com" at the end of his or her email address. If you want to send a single email to multiple recipients, you should add ".getnotify.com" at the end of every email address.


There are countless scenarios that may make these techniques beneficial to your online research. While it might be beneficial to law enforcement, civilians can use it for many different things. Private investigators have used it on dating websites while hunting cheating spouses. Singles have used it to verify that the potential mate they have been chatting with is local and not in another state or country. The possibilities are endless.

2 Comments

Post a Comment

Previous Post Next Post