IP Intelligence Briefing: 108.61.189.136
Date: 2026-06-15
**Overview**
- Risk Profile: Moderate Risk (Risk Score: 59)
- Network Role: Tor Exit Node (Provider: Vultr Holdings, LLC)
- Geolocation: United States (NH, Amsterdam) | Latitude/Longitude: Unavailable
- Threat Indicators: Tor exit node activity detected; no known malware campaigns or spam sources.
**Key Findings**
1. Tor Exit Node Activity
- The IP is registered as a Tor exit node, which is a common entry point for privacy-focused traffic but can be abused for malicious purposes (e.g., hiding attacker IP addresses).
- No direct malware indicators or phishing campaigns linked to this IP.
2. Ownership & Infrastructure
- Owned by Vultr Holdings, LLC (ASN 20473), a cloud infrastructure provider.
- Subnet: 108.61.188.0/23 (abuse density: 1/1000).
- No neighboring IPs in the subnet were identified (neighbors tool returned 0 results).
3. Network Behavior
- Open ports: HTTP (80) and HTTPS (443).
- TLS certificate: Issued to `www.abzkln5kk.com` (subject: `www.dqss7htuvjopl5r.net`).
- No DNS or email security misconfigurations detected.
4. Historical Observations
- Consistent Tor exit node signals over the past 30 days.
- One low-confidence observation of a connection failure (HTTPS).
- No significant changes in risk scores or network behavior.
5. Relationships
- Linked to NET-108-61-188-0-23 (Vultr subnet).
- No direct relationships to known malicious organizations or domains.
**Recommended Actions**
- Monitor Traffic: Track traffic patterns to detect potential misuse of the Tor exit node (e.g., unusual outbound connections).
- Block Tor Exits (if unnecessary): If this IP is not required for legitimate Tor use, consider blocking Tor exit nodes in firewall rules.
- Verify Certificate Validity: Validate the TLS certificate (`www.abzkln5kk.com`) for potential misissuance or misuse.
- Check Subnet Health: Investigate the absence of neighboring IPs in the subnet to confirm operational status.
Conclusion: This IP is a legitimate Tor exit node operated by Vultr. While Tor nodes are not inherently malicious, their association with privacy tools requires vigilance. No immediate action is required unless the IP is used for unauthorized activities.
---
*Generated by IPDebrief. Data sourced from real-time threat intelligence and network analysis.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Vultr Holdings, LLC |
| ASN | AS20473 |
| Network Name | β |
| CIDR Block | 108.61.188.0/23 |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 108.61.189.136.vultrusercontent.com |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 108.61.189.136.vultrusercontent.com |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | 2025-11-13T00:00:00+00:00 |
| Valid Until | 2026-11-04T00:00:00+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 356 days |
| Serial Number | 00EEF2B8F62915E02E |
| Thumbprint | 99CA21CC14922EDF21A705507E5A958576B3676D |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 4 |
| routing | 17% | 2 | 3 |
| services | 30% | 2 | 3 |
| ownership | 19% | 3 | 4 |
| reputation | 27% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 26% | 12 | 20 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-22 13:35:39 UTC |
| Last Seen | 2026-06-28 19:13:32 UTC |
| Profile Built | 2026-06-29 07:17:07 UTC |
| Data Freshness | Live |
| Signal Types | 29 |
| Total Observations | 52 |
Full dossier details are available via our API.