IPDebrief

107.173.67.180

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING

Target IP: 107.173.67.180/32

Classification: Moderate Risk (Risk Score: 50)

Report Date: 2026-07-29

Data Source: IPDebrief Intelligence Platform

---

## EXECUTIVE SUMMARY

IP 107.173.67.180 is a moderate-risk IP address (risk score 50) associated with VortexServers hosting infrastructure. The address resolves to a PTR hostname associated with a European domain and exhibits DNSBL listings. No active threat indicators or malware campaigns detected. Recommended action: Block at perimeter firewall.

---

## NETWORK OWNERSHIP & ATTRIBUTION

FieldValue
**ASN**36352
**Organization**VortexServers
**Network**CC-107-173-67-128-25
**CIDR Block**107.173.67.128/25
**RIR**ARIN
**Geolocation**United States, New York, Buffalo
**Geolocation Confidence**2,500 km radius (consensus)

The IP is hosted under VortexServers infrastructure within a /25 subnet. Ownership has remained consistent across observations with no changes recorded.

---

## THREAT INTELLIGENCE

No active threat feed correlations or known malicious activity observed. The IP is not classified as a Tor exit node, known attacker, or spam source.

---

## NETWORK BEHAVIOR & INFRASTRUCTURE

The address shows no active services or open ports, indicating a passive or firewalled configuration.

---

## DNS & EMAIL REPUTATION

FieldValue
**PTR Hostname**push42.key.tosplickander.eu.com
**Forward Resolution**push42.key.tosplickander.eu.com
**Forward Confirmed**No
**SPF Record**Yes
**DMARC Record**No
**Email Reputation**Not available

DNS analysis reveals associations with a European domain (eu.com). Email authentication is partially implemented with SPF but lacks DMARC policy.

---

## OBSERVATION HISTORY

Total Observations: 14

Observation Period: Recent (2026-07-29)

Recent signals indicate:

---

## NETWORK RELATIONSHIPS

Relationship TypeTarget
Same NetworkCC-107-173-67-128-25
DNS Associationpush42.key.tosplickander.eu.com (3 instances)

---

## SUBNET ANALYSIS (107.173.67.0/24)

Neighbor IPRisk ScoreAuthority Score
107.173.67.199050
107.173.67.2002550
107.173.67.2025050

The subnet exhibits low-to-moderate risk distribution with no high-risk neighbors.

---

## RECOMMENDED SECURITY ACTIONS

Firewall Blocking Rules

```bash

# iptables

iptables -A INPUT -s 107.173.67.180 -j DROP

# nftables

nft add rule inet filter input ip saddr 107.173.67.180 drop

# nginx

deny 107.173.67.180;

# pfSense

107.173.67.180/32

# Cloudflare WAF

{"description":"Block 107.173.67.180 β€” IPDebrief risk score 50","action":"block","filter":{"expression":"ip.src eq 107.173.67.180"}}

# AWS WAF

{"Addresses":["107.173.67.180/32"],"Description":"IPDebrief risk 50"}

```

Risk Assessment

---

## ANALYST NOTES

The IP address exhibits moderate risk primarily due to DNSBL listings and association with a European domain through PTR records. The lack of open ports and active services suggests the infrastructure is either properly secured or actively firewalled. No direct malicious indicators detected in current observations.

Priority: Medium

Action Required: Block at perimeter defense points

Review Period: 30 days

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionNew York
CityBuffalo
Timezoneβ€”
Latitude42.89
Longitude-78.88

🏒 Ownership & Registration

OrganizationVortexServers
ASNAS36352
Network NameCC-107-173-67-128-25
CIDR Block107.173.67.128/25
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRpush42.key.tosplickander.eu.com
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamespush42.key.tosplickander.eu.com

πŸ” DNS Hygiene

Hygiene Score40% (Fair)
SPFPresent
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierUnknown β€” Insufficient routing data to classify
No specific classification

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
443httpstcpβ€”
Closed Ports22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned)
ServerAkamaiGHost
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
CN=*.xbox.com, O=Microsoft Corporation, L=Redmond, S=WA, C=US
Issued by CN=Microsoft TLS G2 ECC CA OCSP 02, O=Microsoft Corporation, C=US
Self-signed: No
SANs*.xbox.com
Valid From2026-07-09T00:31:49+00:00
Valid Until2027-01-23T00:31:49+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha384ECDSA
Validity Period198 days
Serial Number570003B7EE4C138086D421D7BE00000003B7EE
Thumbprint066F2992A99A8857C217DBB4B48DE1B3BB17AE59

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
0%
00
reputation
0%
00
geolocation
0%
00
Overall12%33
Coverage: 3/6 dimensions Β· Data sufficiency: partial
Data CoherenceMostly Consistent (80%) β€” 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Claimed geolocation contradicts RTT physics measurement

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-07-22 19:31:54 UTC
Last Seen2026-08-13 06:43:29 UTC
Profile Built2026-07-29 14:43:36 UTC
Data FreshnessLive
Signal Types22
Total Observations22
πŸ” 22 signal types Β· 22 observations collected
This report is generated from 22+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.