IPDebrief

107.189.8.133

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

INTELLIGENCE BRIEFING: 107.189.8.133/32

Classification: Tor Exit Node Infrastructure β€” Moderate Risk

Date: Current

Analyst: IPDebrief Intelligence

---

EXECUTIVE SUMMARY

IP address 107.189.8.133 is confirmed as a Tor exit node operated by BuyVM (ASN 53667). The IP presents moderate risk (Score: 49) primarily due to Tor exit node classification. No active malicious indicators were observed in recent traffic patterns. The surrounding /24 subnet exhibits high abuse density with 6 additional Tor exit nodes sharing similar risk characteristics (scores 49-55).

---

OWNERSHIP & INFRASTRUCTURE

AttributeValue
ASN53667 (BuyVM)
OrganizationBuyVM
RIRARIN
CIDR Block107.189.8.0/22
Network NameBUYVM-LUXEMBOURG-03
Registration DateN/A

The IP is part of a larger Tor exit node infrastructure deployed across the 107.189.8.0/24 subnet, with 7 active sibling IPs identified.

---

THREAT INDICATORS

IndicatorStatus
Tor Exit Node**CONFIRMED**
Is Known AttackerNo
Is Spam SourceNo
DNS Blacklist Count1 (of 8 total lists)
Pulsedive RiskN/A
Campaign CorrelationNone

Threat Observations:

---

GEOLOCATION DISCREPANCY

FieldValue
Listed CountryUS
Listed RegionLuxembourg
CityLuxembourg
GeoPlausible**FALSE**
Accuracy Radius2500 km

*Note: Geolocation data shows inconsistency between country code (US) and regional data (Luxembourg). This is common with cloud-based Tor infrastructure.*

---

NETWORK NEIGHBORHOOD ANALYSIS

Subnet: 107.189.8.0/24

MetricValue
Subnet ClassificationHigh Abuse
Total Siblings7
Active Siblings7
Threat Siblings7
Abuse Density1.0

Sibling Risk Profile:

IPRisk ScoreAuthority Score
107.189.8.164960
107.189.8.564950
107.189.8.654960
107.189.8.705550
107.189.8.1814960
107.189.8.2264950
107.189.8.133490

All neighbors share identical risk profiles consistent with Tor exit node classification.

---

OBSERVATION HISTORY

Analysis Period: 50 observations recorded

MetricFinding
Recent SignalsMinimal threat activity
Threat Persistence0 days
Is Persistently MaliciousNo
Observation TrendStable β€” no escalation

Recent observations (June 26-27, 2026) indicate consistent Tor exit node behavior without additional malicious indicators or service changes.

---

CONTROL PLANE ANALYSIS

ParameterValue
Origin ASN53667
BGP Prefix107.189.8.0/22
AS Path6939 β†’ 53667
RPKI StateN/A
IRR ConsistencyN/A
Route StabilityStable (0 changes in 30d)
DNSSEC ValidYes
Delegated Age5,667 days

---

RECOMMENDED ACTIONS

SOC Analyst Guidance:

1. Allow List Evaluation: This IP is a Tor exit node. If your organization permits Tor traffic, monitor for abuse patterns. If blocked, ensure egress filtering is configured.

2. Firewall Rules: No additional blocking required beyond existing Tor exit node policies. Standard Tor exit node mitigation applies.

3. Traffic Monitoring: Monitor for:

- Unusual data exfiltration patterns

- Command and control beaconing

- Large payload transfers through Tor relay

4. Subnet Context: The entire 107.189.8.0/24 subnet should be evaluated with consistent Tor exit node policies. All 7 sibling IPs share the same classification.

5. False Positive Awareness: The moderate risk score (49) is appropriate for Tor exit node classification. Do not treat as malicious without additional context.

---

CONCLUSION

IP 107.189.8.133 is a legitimate Tor exit node infrastructure component operated by BuyVM. The IP presents expected moderate risk consistent with Tor relay classification. No evidence of active malicious activity or abuse beyond standard Tor exit node behavior. The surrounding subnet exhibits consistent Tor infrastructure deployment with no anomalous risk escalation.

Status: Monitor β€” Standard Tor Exit Node Policy Applies

Priority: Low (Infrastructure Classification)

Action: No immediate changes required; maintain existing Tor exit node egress policies.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionLuxembourg
CityLuxembourg
Timezoneβ€”
Latitude49.79
Longitude6.10

🏒 Ownership & Registration

OrganizationBuyVM
ASNAS53667
Network Nameβ€”
CIDR Block107.189.8.0/22
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRLuxembourgTorNew6.Quetzalcoatl-relays.org
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)
Forward HostnamesLuxembourgTorNew6.Quetzalcoatl-relays.org

πŸ” DNS Hygiene

Hygiene Score40% (Fair)
SPFPresent
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown β€” Insufficient routing data to classify
Tor

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
26%
24
routing
17%
23
services
12%
22
ownership
19%
34
reputation
28%
13
geolocation
19%
22
Overall20%1218
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-22 13:35:41 UTC
Last Seen2026-06-28 19:19:18 UTC
Profile Built2026-06-29 07:22:52 UTC
Data FreshnessLive
Signal Types27
Total Observations51
πŸ” 27 signal types Β· 51 observations collected
This report is generated from 27+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.