# IP Intelligence Briefing: 111.90.159.151/32
## Executive Summary
IP address 111.90.159.151 is classified as a Tor Exit Node with a moderate risk score of 66. The address is associated with Shinjiru Technology Sdn Bhd (ASN 45839) and operates under the SHINJIRU-MY network infrastructure in Malaysia. Multiple threat indicators and DNSBL listings suggest active abuse activity.
## Technical Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 66 (Moderate Risk) |
| **ASN** | 45839 |
| **Organization** | Shinjiru Technology Sdn Bhd administrator |
| **Network Block** | 111.90.128.0/19 |
| **Country** | Malaysia (MY) |
| **Classification** | Tor Exit Node Provider |
| **DNS Hostname** | server1.kamon.la |
## Threat Indicators
- Tor Exit Node: Confirmed active Tor exit node indicator
- DNSBL Listings: 1 blacklist listing with maximum severity rated "high"
- Certificate Mismatch: TLS certificate shows mismatched issuer (CN=www.bz5ruu7b4ctarxagc6.com) and subject (CN=www.7q7l3ddut4g5vm.net), indicating potential malicious activity
- Route Instability: 8 BGP route changes observed within the past 30 days, suggesting unstable or rapidly changing infrastructure
## Neighborhood Analysis
The /24 subnet 111.90.159.0/24 demonstrates:
- Abuse Density: 1 (moderate threat concentration)
- Active Siblings: 2 out of 2 total siblings are active
- Threat Siblings: 2 threat-associated IPs identified
- Neighbor Risk: 111.90.159.170 (risk score: 59, authority score: 50)
## Observation History
Analysis of 59 historical observations reveals:
- Recent DNSBL listings detected on 2026-07-29 with high severity classification
- Multiple routing and reputation signal observations recorded
- GeoPlausible validation failed, indicating geolocation inconsistencies
- No persistent malicious behavior patterns detected over long-term observation
## Recommended Actions
1. Block or Rate-Limit: Consider blocking inbound traffic to this IP from internal networks
2. Monitor Outbound: Alert on outbound connections to this Tor exit node for data exfiltration attempts
3. Certificate Verification: Investigate the mismatched TLS certificate for potential certificate-based attacks
4. Neighborhood Monitoring: Monitor 111.90.159.170 and other siblings in the subnet for correlated activity
5. Firewall Rules: Implement iptables/nftables rules to drop or log traffic to this IP
## Conclusion
IP 111.90.159.151 represents a moderate-risk threat vector as an active Tor exit node with documented abuse activity. The certificate mismatch and multiple blacklist listings warrant defensive monitoring and potential blocking depending on organizational security posture.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Shinjiru Technology Sdn Bhd administrator |
| ASN | AS45839 |
| Network Name | SHINJIRU-MY |
| CIDR Block | 111.90.128.0/19 |
| RIR | APNIC |
| Country | MY |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | server1.kamon.la |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | server1.kamon.la |
🔐 DNS Hygiene
| Hygiene Score | 0% (None) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 443 | https | tcp | — |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | 2026-07-07T00:00:00+00:00 |
| Valid Until | 2026-11-15T00:00:00+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 294 days |
🛡️ Public Network Snapshot
| Origin ASN | AS45839 |
| Network Prefix | 111.90.158.0/23 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 44% | 1 | 199 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 11% | 2 | 200 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-17 12:38:37 UTC |
| Last Seen | 2026-09-05 13:04:55 UTC |
| Profile Built | 2026-09-05 13:11:37 UTC |
| Data Freshness | Live |
| Signal Types | 27 |
| Total Observations | 249 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 111.90.159.151
Who owns the IP address 111.90.159.151?
111.90.159.151 is registered to Shinjiru Technology Sdn Bhd administrator. The address falls within the 111.90.128.0/19 network block. Registration is held at APNIC.
Where is 111.90.159.151 located?
Geolocation data places 111.90.159.151 in Boston. The local time zone is Asia/Kuala_Lumpur. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 111.90.159.151 malicious or safe?
111.90.159.151 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 111.90.159.151?
The reverse DNS (PTR) record for 111.90.159.151 is server1.kamon.la. This hostname is not forward-confirmed, so it should be treated as a weak signal.
What ports are open on 111.90.159.151?
Responsive ports observed on 111.90.159.151 include 80, 443. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.
Is 111.90.159.151 a VPN, proxy, or data center address?
111.90.159.151 is classified as the Tor network based on network ownership and behavioural analysis.