# IP Intelligence Briefing: 107.189.5.121/32
Date: 2024-01-15
Analyst: IPDebrief Intelligence Team
Classification: Internal Threat Intelligence
---
## Executive Summary
IP address 107.189.5.121/32 was identified as a Tor exit node operated by BuyVM (ASN 53667). The IP received a moderate risk score of 50 and exhibited confirmed Tor exit indicators during observation. The subnet (107.189.5.0/24) demonstrated high abuse density with 7 total sibling IPs, 6 actively classified, and 5 flagged as threats.
---
## Technical Profile
Ownership & Registration:
- ASN: 53667 (BuyVM)
- Organization: BuyVM
- RIR: ARIN
- CIDR Block: 107.189.5.0/24
Geolocation:
- Country: United States (US)
- Region: Luxembourg
- Accuracy Radius: 2,500 km
- RTT Analysis: Minimum 102ms, Average 108.4ms across 5 probes
Network Classification:
- Role: Tor Exit Nodes
- Infrastructure Type: Unknown
- Cloud Provider: No
- CDN: No
- Proxy/VPN: No
- Mobile/Residential: No
DNS Resolution:
- PTR Hostname: LuxembourgTorNew1.Quetzalcoatl-relays.org
- Forward Resolution: Confirmed to Quetzalcoatl-relays.org
- Email Authentication: SPF enabled, DMARC not configured
---
## Threat Indicators
Primary Threat Signals:
- Tor exit indicators observed during probing
- Blacklist count: 1
- Abuse confidence: Elevated due to Tor exit node classification
- Is Known Attacker: No
- Is Spam Source: No
Control Plane Data:
- BGP Origin ASN: 53667
- BGP Prefix: 107.189.0.0/21
- AS Path: 6939 53667
- Route Stability: Stable (0 route changes in 30 days)
- DNSBL Listed: 2 of 8 total DNSBL lists
- Operator Score: 0.2609
---
## Observation History
Analysis of 50 recent signal observations revealed consistent patterns:
- Temporal Activity: Signals observed between June 26-27, 2026 timeframe
- Risk Trend: Most recent signals classified as "Minimal" with raw scores of 0
- Confidence Levels: Ranged from 0.22 to 0.30 across observations
- Threat Persistence: Single threat observation recorded (0 days persistent)
- Ownership Changes: None observed
The IP demonstrated transient activity with no evidence of persistent malicious behavior.
---
## Subnet Analysis (107.189.5.0/24)
Neighborhood Risk Assessment:
- Total Siblings: 7
- Active Siblings: 6
- Threat Siblings: 5
- Abuse Density: 0.7143 (High Abuse Classification)
- Inherited Risk Score: 12
Sibling IP Risk Distribution:
- High Risk: 0
- Medium Risk: 4 (scores: 49, 40, 25, 40)
- Low Risk: 2 (scores: 25, 49)
Notable sibling IPs:
- 107.189.5.7 (Risk: 49)
- 107.189.5.57 (Risk: 40)
- 107.189.5.104 (Risk: 25)
- 107.189.5.183 (Risk: 25)
- 107.189.5.203 (Risk: 40)
- 107.189.5.249 (Risk: 49)
---
## Relationship Graph
The IP demonstrated 401 relationships primarily with network infrastructure. Key relationship types included:
- Same Network: Multiple instances linked to BUYVM-LUXEMBOURG-02 network
This indicates the IP is part of a coordinated infrastructure deployment.
---
## Recommended Actions
Access Control Recommendation:
- Category: Access Control
- Action: Consider enhanced verification for anonymous traffic
- Severity: Medium
- Reason: Tor exit indicators observed
Firewall Rules (Blocking):
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 107.189.5.121 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 107.189.5.121 drop` |
| nginx | `deny 107.189.5.121;` |
| pfSense | `107.189.5.121/32` |
| Cloudflare WAF | `ip.src eq 107.189.5.121` (action: block) |
| AWS WAF | `Addresses: 107.189.5.121/32` |
---
## Intelligence Assessment
The IP address 107.189.5.121/32 represents a known Tor exit node infrastructure component. While the IP itself shows moderate risk with no confirmed malicious activity in recent observations, the subnet's high abuse density (0.7143) and multiple flagged threat siblings suggest elevated operational risk.
Recommendations for SOC Operations:
1. Treat traffic from this IP as potentially anonymized; implement additional verification protocols
2. Consider blocking at perimeter defenses if business policy prohibits Tor traffic
3. Monitor subnet 107.189.5.0/24 for coordinated abuse patterns
4. No immediate threat escalation required absent additional threat indicators
Campaign Correlation: None observed. No certificate matches, banner matches, or correlated IPs detected.
---
*Report generated from IPDebrief intelligence platform. All data sourced from active IP reputation and threat intelligence feeds.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | BuyVM |
| ASN | AS53667 |
| Network Name | β |
| CIDR Block | 107.189.0.0/21 |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | LuxembourgTorNew1.Quetzalcoatl-relays.org |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | LuxembourgTorNew1.Quetzalcoatl-relays.org |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 17% | 2 | 3 |
| services | 12% | 2 | 2 |
| ownership | 22% | 3 | 4 |
| reputation | 28% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 23% | 12 | 19 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-22 13:35:41 UTC |
| Last Seen | 2026-06-28 19:21:10 UTC |
| Profile Built | 2026-06-29 07:25:14 UTC |
| Data Freshness | Live |
| Signal Types | 28 |
| Total Observations | 51 |
Full dossier details are available via our API.