IPDebrief

111.90.159.170

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 111.90.159.170/32

Classification: Moderate Risk

Date: Current Analysis

Reporting Entity: IPDebrief Intelligence Team

---

## Executive Summary

IP address 111.90.159.170 is registered to Shinjiru Technology Sdn Bhd (ASN 45839) within the Malaysian ISP network SHINJIRU-MY. The IP is classified as a Tor exit node and has observed indicators of Tor exit traffic. Recent blacklist observations indicate active threat activity with high severity ratings. The IP operates standard web services (HTTP/HTTPS) with TLS certificates showing mismatched issuer and subject domains, suggesting potential anonymization or command-and-control infrastructure.

---

## Technical Profile

Network Assignment:

Network Role Classification:

Active Services:

---

## Threat Intelligence Indicators

Threat Classifications:

Observed Threat Indicators:

Control Plane Analysis:

---

## Historical Activity Analysis

Observation Summary:

Blacklist Trends:

Recent observations show fluctuating blacklist activity with high severity ratings on multiple occasions:

The pattern indicates intermittent but recurring blacklisting activity, consistent with Tor exit node reputation management.

---

## Neighborhood Analysis

Subnet: 111.90.159.0/24

Identified Neighbor:

The /24 subnet shows concentrated threat activity with all identified siblings classified as threats, suggesting coordinated or shared infrastructure usage within this network block.

---

## Relationships Graph

Identified Connections:

---

## Recommended Actions

Immediate Actions:

1. Block 111.90.159.170 at perimeter firewall due to Tor exit node classification and active blacklist presence

2. Monitor 111.90.159.151 (neighbor IP, risk score 66) for correlated activity

3. Investigate TLS certificate mismatch (issuer ≠ subject) for potential C2 infrastructure

Firewall Rules:

```

iptables -A INPUT -s 111.90.159.0/24 -j DROP

# Or for targeted blocking:

iptables -A INPUT -s 111.90.159.170 -j DROP

```

Monitoring Recommendations:

---

## Conclusion

IP 111.90.159.170 represents a confirmed Tor exit node operating within a Malaysian ISP infrastructure. The combination of Tor exit indicators, active blacklist presence, certificate anomalies, and neighborhood threat density warrants defensive blocking at network perimeters. The unstable routing and high-risk sibling IPs suggest broader infrastructure abuse patterns within the /24 subnet that may require subnet-level policy consideration.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇲🇾 Malaysia
Region—
CityLondon
TimezoneAsia/Kuala_Lumpur
Latitude4.21
Longitude101.98

🏢 Ownership & Registration

OrganizationShinjiru Technology Sdn Bhd administrator
ASNAS45839
Network NameSHINJIRU-MY
CIDR Block111.90.128.0/19
RIRAPNIC
CountryMY
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRserver1.kamon.la
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesserver1.kamon.la

🔐 DNS Hygiene

Hygiene Score0% (None)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECNot signed
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierUnknown — Insufficient routing data to classify
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
80httptcp—
443httpstcp—
Closed Ports22, 25, 3389, 8080, 8443 (2 open / 7 scanned)
Server—
HTTP Title—

🔐 TLS Certificate

An expired certificate for CN=www.gcrjkld5xclt45qjiqa7.net was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.
🔒
CN=www.gcrjkld5xclt45qjiqa7.net
Issued by CN=www.kaqb2fl4fiyzkp32.com
Self-signed: No
SANsNone
Valid From2026-07-28T00:00:00+00:00
Valid Until2026-08-23T23:59:59+00:00 (expired)
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period344 days

🛡️ Public Network Snapshot

Origin ASNAS45839
Network Prefix111.90.158.0/23
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
51%
2198
routing
0%
00
services
0%
00
ownership
0%
00
reputation
25%
11
geolocation
0%
00
Overall12%3199
Coverage: 6/6 dimensions · Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) — 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Geo sources disagree on country: GB, MY

📅 Observation Timeline 🔄 Live

First Seen2026-07-17 13:39:10 UTC
Last Seen2026-09-05 20:07:48 UTC
Profile Built2026-09-05 20:17:03 UTC
Data FreshnessLive
Signal Types28
Total Observations242
🔍 28 signal types · 242 observations collected
This report is generated from 28+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 111.90.159.170

Who owns the IP address 111.90.159.170?

111.90.159.170 is registered to Shinjiru Technology Sdn Bhd administrator. The address falls within the 111.90.128.0/19 network block. Registration is held at APNIC.

Where is 111.90.159.170 located?

Geolocation data places 111.90.159.170 in London. The local time zone is Asia/Kuala_Lumpur. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 111.90.159.170 malicious or safe?

111.90.159.170 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.

What is the hostname for 111.90.159.170?

The reverse DNS (PTR) record for 111.90.159.170 is server1.kamon.la. This hostname is not forward-confirmed, so it should be treated as a weak signal.

What ports are open on 111.90.159.170?

Responsive ports observed on 111.90.159.170 include 80, 443. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.

🏘️ Related IP Addresses

Nearby addresses in 111.90.128.0/19

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.