Skip to content

Multi-IP Infrastructure Detected

It indicates that the domain operates across multiple IP addresses simultaneously. This is commonly seen in legitimate services such as global organizations, CDNs, or enterprise-grade platforms that distribute their load geographically or for redundancy.

Analyst Q&A

What this signal answers

Three questions every analyst asks before acting on this signal.

What it detects01

What does 'Multi-IP Infrastructure Detected' mean?

It indicates that the domain operates across multiple IP addresses simultaneously. This is commonly seen in legitimate services such as global organizations, CDNs, or enterprise-grade platforms that distribute their load geographically or for redundancy.

Why it matters02

Why can multiple active IPs indicate a safe or trustworthy domain?

Managing and maintaining multiple IPs requires technical resources, investment, and infrastructure maturity. Legitimate companies often use multi-IP architectures to ensure uptime, balance network load, and improve user experience, which is rarely the case for short-lived malicious domains.

How analysts use it03

How should SOC or CTI analysts interpret multi-IP activity?

If the IPs belong to reputable ASNs, are consistent over time, and serve legitimate content, the domain’s multi-IP pattern is a strong positive signal of organizational stability rather than malicious intent.

Evidence shape

What Multi-IP Infrastructure Detected looks like in the response

A realistic shape of the entry the engine appends to the risk_signals array when this signal fires. Evidence keys are subgroup-default; per-signal overrides documented in the API reference.

json
{
  "slug": "active_alot_of_ip",
  "name": "Multi-IP Infrastructure Detected",
  "group": "dns_history",
  "subgroup": "ip_diversity_rotation",
  "direction": "safe",
  "evidence": {
    "distinct_ips_30d": 47,
    "rotation_period_hours": 6,
    "geo_distribution": [
      "US",
      "RU",
      "VN"
    ],
    "fast_flux_score": 0.81
  }
}
See in API reference
Siblings

Peers in IP Diversity & Rotation

2 other signals share the same subgroup. They detect related behaviors and often co-fire on the same IOC.

Extensive Subdomain Infrastructure Detected

It means the domain operates with a large number of well-organized and active subdomains. This is typical for legitimate

SafeCore
Centralized IP-Subdomain Infrastructure Detected

It indicates that multiple subdomains of the same domain are actively served through a shared IP address over a long per

Safe
In the wild

See Multi-IP Infrastructure Detected fire on real IOCs

The Verdict Gallery is a curated stream of real verdicts. Filter by this signal to see exactly which IOCs it caught, what other signals fired alongside it, and what the engine recommended.

Open Verdict Gallery
Pre-filtered to Multi-IP Infrastructure Detected. See real IOCs this signal caught and the verdicts the engine returned.
Verdicts ✓

Start free, in five minutes

100 IOCs/day on the free tier, LLM layer included. No card required.