IP Intelligence Briefing: 107.189.30.49
Date: June 15, 2026
---
**1. Core Profile**
- Risk Score: 59 (Moderate Risk)
- Network Role: Tor Exit Node (classified as "Web Server" with HTTPS service on port 443)
- Ownership:
- ASN: AS53667 (BuyVM)
- Registrar: ARIN
- Geolocation: Registered to the US but geolocated to Luxembourg (49.75°N, 6.17°E)
- Threat Indicators:
- Identified as a Tor exit node (potential anonymity layer for malicious activity)
- DNSSEC validation confirmed, but no TLS certificate details available
- 2 DNSBL listings (out of 8 total)
---
**2. Observation History**
- Latest Activity: June 15, 2026
- Tor exit node detected with 50+ pulse counts (potential for data exfiltration or covert communication)
- Geo validation: Plausible (301.9 km from probe, 108ms avg RTT)
- No significant changes in risk signals over time
---
**3. Network Relationships**
- Linked Entities:
- Same network: BUYVM-LUXEMBOURG-03 (repeated in 191 relationships)
- Subnet: 107.189.30.0/24 (abuse density: 0%)
- Neighbor IPs (107.189.30.49/24):
- 107.189.30.69 (riskScore: 59), 107.189.30.86 (riskScore: 59), 107.189.30.236 (riskScore: 59)
- All subnets show low to moderate risk, no immediate abuse indicators
---
**4. Threat Context**
- Tor Exit Node:
- High-risk due to potential use in anonymizing malicious traffic (e.g., C2, exfiltration)
- No direct evidence of active attacks, but Tor exit nodes are often associated with covert operations
- Provider Context:
- BuyVM (AS53667) is a commercial hosting provider with no known malicious activity in historical records
---
**5. Recommendations**
- Monitoring:
- Track Tor exit node activity for anomalous traffic patterns (e.g., unusual TLS handshakes, volume spikes)
- Monitor BUYVM network for correlated threats (107.189.30.0/24)
- Mitigation:
- Consider blocking Tor exit nodes if not required for legitimate use (e.g., via iptables or WAF rules)
- Verify TLS certificate validity for HTTPS service (port 443)
---
Conclusion:
107.189.30.49 is a Tor exit node operated by BuyVM, registered to Luxembourg but geolocated to the US. While no direct malicious activity is observed, its association with Tor requires vigilance. The subnet shows low abuse density, but network defenders should monitor for potential covert operations leveraging the Tor anonymity layer.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | BuyVM |
| ASN | AS53667 |
| Network Name | β |
| CIDR Block | 107.189.30.0/23 |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | 2026-06-08T00:00:00+00:00 |
| Valid Until | 2026-08-27T23:59:59+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 80 days |
| Serial Number | 00DB2E83C730E45DC5 |
| Thumbprint | FC3A7DDD8FF59D6AF0D7DA56646C2CA8CC43E1E3 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 17% | 2 | 3 |
| services | 34% | 2 | 3 |
| ownership | 29% | 3 | 6 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 28% | 12 | 22 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-22 13:35:43 UTC |
| Last Seen | 2026-06-28 19:25:09 UTC |
| Profile Built | 2026-06-29 07:28:46 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 53 |
Full dossier details are available via our API.