IPDebrief

107.189.10.175

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 107.189.10.175/32

## Executive Summary

Target IP 107.189.10.175 is a confirmed Tor exit node operated by BuyVM (ASN 53667). The IP exhibits moderate risk (score: 59) with one DNSBL listing and Tor exit node indicators. No active services are detected; the IP is firewall-configured with no open ports. The IP belongs to the 107.189.10.0/24 subnet, which shows low abuse density (0.0) and three neighboring IPs with low-risk profiles.

## Ownership and Network Classification

## Threat Indicators

## DNS and Reverse Resolution

## Service and Port Analysis

## Neighborhood Analysis (107.189.10.0/24)

Neighbor IPs:

IP AddressRisk ScoreAuthority Score
107.189.10.1242550
107.189.10.2342550
107.189.10.2482560

## Observation History

## BGP and Control Plane

## SOC Recommendations

1. Monitor for C2 Traffic: As a Tor exit node, this IP may be used for command-and-control communications or anonymized traffic. Monitor outbound connections from internal systems to this IP.

2. Firewall Rule Consideration: Block inbound connections to this IP. Outbound connections may be permitted depending on security policy.

3. Contextual Analysis: If this IP appears in logs, correlate with destination ports and payload data to determine legitimate use (e.g., legitimate Tor relay traffic vs. malicious C2).

4. Neighborhood Context: The 107.189.10.0/24 subnet shows low abuse density with three low-risk neighbors, suggesting the IP's risk is isolated to its Tor function rather than broader subnet compromise.

5. Threat Intelligence Integration: Add to Tor exit node watchlist for potential abuse detection.

## Risk Assessment

The IP presents moderate risk primarily due to its function as a Tor exit node. The absence of open services reduces the likelihood of direct exploitation. The consistent network classification and stable BGP routing indicate this is an operational Tor node rather than a compromised infrastructure. SOC teams should focus on monitoring outbound traffic patterns and correlating with threat intelligence feeds for Tor-based attacks.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionMersch
CityBissen
Timezoneβ€”
Latitude49.79
Longitude6.10

🏒 Ownership & Registration

OrganizationBuyVM
ASNAS53667
Network Nameβ€”
CIDR Block107.189.8.0/22
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRLuxembourgTorNew25.Quetzalcoatl-relays.org
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)
Forward HostnamesLuxembourgTorNew25.Quetzalcoatl-relays.org

πŸ” DNS Hygiene

Hygiene Score40% (Fair)
SPFPresent
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown β€” Insufficient routing data to classify
No specific classification

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
26%
24
routing
17%
23
services
12%
22
ownership
22%
34
reputation
28%
13
geolocation
27%
23
Overall22%1219
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-22 13:35:41 UTC
Last Seen2026-06-28 19:20:54 UTC
Profile Built2026-06-29 07:25:14 UTC
Data FreshnessLive
Signal Types28
Total Observations51
πŸ” 28 signal types Β· 51 observations collected
This report is generated from 28+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.