IP Intelligence Briefing: 104.244.73.14
Date: 2026-06-09
---
**Key Findings**
1. Threat Profile
- Risk Score: Moderate (59/100).
- Threat Indicators: Identified as a Tor exit node with observed Tor exit activity.
- Network Role: Classified as a Tor Exit Node, associated with the hostname `tor.bottomservices.club`.
- Ownership: Registered to BuyVM (ASN 53667), with geolocation in Phoenix, AZ, US.
2. Network Context
- Subnet Abuse Density: High (0.8571) for `104.244.73.0/24`, classified as high_abuse.
- Neighbors: 6 active IPs in the subnet, with 5 showing moderate risk scores (40β59). Notable peers include:
- `104.244.73.43` (59/100), `104.244.73.136` (59/100), and `104.244.73.190` (59/100).
- Routing: BGP path `6939 53667`, stable with no recent route changes.
3. Observation History
- Recent Activity:
- Tor exit indicators observed since 2026-06-09.
- DNS resolution to `tor.bottomservices.club` (forward confirmed).
- Stability: Operator score (0.3913) suggests basic network reliability.
4. Relationships
- DNS Associations: Linked to `tor.bottomservices.club`.
- Network Peers: Same subnet (`BUYVM-LUXEMBOURG-01`).
---
**Actionable Intelligence**
- SOC Analyst Recommendations:
- Monitor traffic from this IP for Tor exit node activity or malicious payload exfiltration.
- Investigate `tor.bottomservices.club` for potential command-and-control (C2) or phishing ties.
- Consider blocking or restricting traffic from the `104.244.73.0/24` subnet due to high abuse density.
- Check if neighboring IPs (e.g., `104.244.73.43`, `104.244.73.136`) are associated with known malicious campaigns.
- Firewall/Network Rules:
- Apply rules to block Tor exit node traffic (e.g., via iptables, Cloudflare WAF, or AWS WAF).
- Flag DNS queries to `tor.bottomservices.club` for further analysis.
---
Conclusion: This IP is part of a Tor exit node network with elevated risk due to its association with Tor and a high-abuse subnet. While not directly malicious, its role in anonymizing traffic and the subnetβs abuse density warrant close monitoring. SOC teams should prioritize isolating or mitigating traffic from this subnet to reduce exposure to Tor-based threats.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | BuyVM |
| ASN | AS53667 |
| Network Name | β |
| CIDR Block | 104.244.73.0/24 |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | tor.bottomservices.club |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | tor.bottomservices.club |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | β |
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_10.0p2 Debian-7+deb13u4 |
π TLS Certificate
| SANs | None |
| Valid From | 2026-04-04T00:00:00+00:00 |
| Valid Until | 2026-11-05T23:59:59+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 215 days |
| Serial Number | 00A4C6A3D3CDB97465 |
| Thumbprint | ED0A56F41831E99B45A595E00951378704DC304F |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 42% | 2 | 7 |
| services | 34% | 2 | 3 |
| ownership | 29% | 3 | 6 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 33% | 12 | 26 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-22 13:35:44 UTC |
| Last Seen | 2026-06-28 19:26:39 UTC |
| Profile Built | 2026-06-29 14:22:29 UTC |
| Data Freshness | Live |
| Signal Types | 31 |
| Total Observations | 62 |
Full dossier details are available via our API.