# IP INTELLIGENCE BRIEFING
Target IP: 107.173.67.180/32
Classification: Moderate Risk (Risk Score: 50)
Report Date: 2026-07-29
Data Source: IPDebrief Intelligence Platform
---
## EXECUTIVE SUMMARY
IP 107.173.67.180 is a moderate-risk IP address (risk score 50) associated with VortexServers hosting infrastructure. The address resolves to a PTR hostname associated with a European domain and exhibits DNSBL listings. No active threat indicators or malware campaigns detected. Recommended action: Block at perimeter firewall.
---
## NETWORK OWNERSHIP & ATTRIBUTION
| Field | Value |
|---|---|
| **ASN** | 36352 |
| **Organization** | VortexServers |
| **Network** | CC-107-173-67-128-25 |
| **CIDR Block** | 107.173.67.128/25 |
| **RIR** | ARIN |
| **Geolocation** | United States, New York, Buffalo |
| **Geolocation Confidence** | 2,500 km radius (consensus) |
The IP is hosted under VortexServers infrastructure within a /25 subnet. Ownership has remained consistent across observations with no changes recorded.
---
## THREAT INTELLIGENCE
- Risk Score: 50 (Moderate)
- Provider Score: 0
- Authority Score: 0
- Operator Score: 0.1304 (Minimal)
- Threat Indicators: None detected
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Blacklist Count: 0
- DNSBL Listings: 2 out of 8 total lists
No active threat feed correlations or known malicious activity observed. The IP is not classified as a Tor exit node, known attacker, or spam source.
---
## NETWORK BEHAVIOR & INFRASTRUCTURE
- Infrastructure Type: Hosting (firewalled/no services detected)
- Open Ports: None detected
- TLS Certificate: None detected
- Connection Type: Standard TCP/IPv4
- Cloud Provider: No
- CDN: No
- Proxy/VPN: No
- Mobile Carrier: No
The address shows no active services or open ports, indicating a passive or firewalled configuration.
---
## DNS & EMAIL REPUTATION
| Field | Value |
|---|---|
| **PTR Hostname** | push42.key.tosplickander.eu.com |
| **Forward Resolution** | push42.key.tosplickander.eu.com |
| **Forward Confirmed** | No |
| **SPF Record** | Yes |
| **DMARC Record** | No |
| **Email Reputation** | Not available |
DNS analysis reveals associations with a European domain (eu.com). Email authentication is partially implemented with SPF but lacks DMARC policy.
---
## OBSERVATION HISTORY
Total Observations: 14
Observation Period: Recent (2026-07-29)
Recent signals indicate:
- Consistent ownership attribution to VortexServers
- Geographic consensus showing Buffalo, NY (with one outlier probe showing Kansas coordinates at 35% confidence)
- Traceroute: 16 hops with Comcast as primary transit network
- No significant threat persistence patterns
---
## NETWORK RELATIONSHIPS
| Relationship Type | Target |
|---|---|
| Same Network | CC-107-173-67-128-25 |
| DNS Association | push42.key.tosplickander.eu.com (3 instances) |
---
## SUBNET ANALYSIS (107.173.67.0/24)
- Abuse Density: 0
- Total Siblings: 3
- Risk Distribution: 0 High, 1 Medium, 2 Low
| Neighbor IP | Risk Score | Authority Score |
|---|---|---|
| 107.173.67.199 | 0 | 50 |
| 107.173.67.200 | 25 | 50 |
| 107.173.67.202 | 50 | 50 |
The subnet exhibits low-to-moderate risk distribution with no high-risk neighbors.
---
## RECOMMENDED SECURITY ACTIONS
Firewall Blocking Rules
```bash
# iptables
iptables -A INPUT -s 107.173.67.180 -j DROP
# nftables
nft add rule inet filter input ip saddr 107.173.67.180 drop
# nginx
deny 107.173.67.180;
# pfSense
107.173.67.180/32
# Cloudflare WAF
{"description":"Block 107.173.67.180 β IPDebrief risk score 50","action":"block","filter":{"expression":"ip.src eq 107.173.67.180"}}
# AWS WAF
{"Addresses":["107.173.67.180/32"],"Description":"IPDebrief risk 50"}
```
Risk Assessment
- Block Recommended: Yes (Risk Score 50, DNSBL listings)
- Monitor Only: Not recommended given DNSBL presence
- Allow with Scrubbing: Not recommended without further investigation
---
## ANALYST NOTES
The IP address exhibits moderate risk primarily due to DNSBL listings and association with a European domain through PTR records. The lack of open ports and active services suggests the infrastructure is either properly secured or actively firewalled. No direct malicious indicators detected in current observations.
Priority: Medium
Action Required: Block at perimeter defense points
Review Period: 30 days
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | VortexServers |
| ASN | AS36352 |
| Network Name | CC-107-173-67-128-25 |
| CIDR Block | 107.173.67.128/25 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | push42.key.tosplickander.eu.com |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | push42.key.tosplickander.eu.com |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | AkamaiGHost |
| HTTP Title | β |
π TLS Certificate
| SANs | *.xbox.com |
| Valid From | 2026-07-09T00:31:49+00:00 |
| Valid Until | 2027-01-23T00:31:49+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 198 days |
| Serial Number | 570003B7EE4C138086D421D7BE00000003B7EE |
| Thumbprint | 066F2992A99A8857C217DBB4B48DE1B3BB17AE59 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-22 19:31:54 UTC |
| Last Seen | 2026-08-13 06:43:29 UTC |
| Profile Built | 2026-07-29 14:43:36 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 22 |
Full dossier details are available via our API.