# IP Intelligence Briefing: 111.90.159.170/32
Classification: Moderate Risk
Date: Current Analysis
Reporting Entity: IPDebrief Intelligence Team
---
## Executive Summary
IP address 111.90.159.170 is registered to Shinjiru Technology Sdn Bhd (ASN 45839) within the Malaysian ISP network SHINJIRU-MY. The IP is classified as a Tor exit node and has observed indicators of Tor exit traffic. Recent blacklist observations indicate active threat activity with high severity ratings. The IP operates standard web services (HTTP/HTTPS) with TLS certificates showing mismatched issuer and subject domains, suggesting potential anonymization or command-and-control infrastructure.
---
## Technical Profile
Network Assignment:
- ASN: 45839 (Shinjiru Technology Sdn Bhd administrator)
- Organization: SHINJIRU-MY
- CIDR Block: 111.90.128.0/19
- Geolocation: Kuala Lumpur, Malaysia (4.21°N, 101.98°E)
- RIR: APNIC
Network Role Classification:
- Primary Role: Tor Exit Nodes
- Infrastructure Type: Unknown
- Risk Score: 59/100 (Moderate Risk)
- Provider Score: 0
- Authority Score: 0
Active Services:
- Port 80/TCP: HTTP service
- Port 443/TCP: HTTPS service
- TLS Certificate: Issuer CN=www.hqmydkvi7x.com, Subject CN=www.3fwfjg3lzg4yidhbx.net (certificate shows mismatched domains)
- PTR Record: server1.kamon.la
---
## Threat Intelligence Indicators
Threat Classifications:
- Tor Exit Node: YES (Confirmed)
- Known Attacker: NO
- Spam Source: NO
- Blacklist Status: 1 active listing
- DNSBL Lists: 8 total lists checked, 0 currently listed
Observed Threat Indicators:
- Tor exit indicators observed in threat feeds
Control Plane Analysis:
- BGP Prefix: 111.90.159.0/24
- AS Path: 38001 → 45839
- Route Stability: UNSTABLE (8 route changes in 30 days)
- RPKI State: Not validated
- IRR Consistency: Not assessed
---
## Historical Activity Analysis
Observation Summary:
- Total Observations: 82 signals recorded
- Recent Activity: Multiple observations within 2026-07-28 timeframe
- Threat Persistence: 0 days (not persistently malicious)
Blacklist Trends:
Recent observations show fluctuating blacklist activity with high severity ratings on multiple occasions:
- 2026-07-28 21:08: 8 total lists, 0 listed
- 2026-07-28 19:57: 8 total lists, 1 listed (high severity)
- 2026-07-28 19:18: 8 total lists, 1 listed (high severity)
- 2026-07-28 19:09: 8 total lists, 0 listed
The pattern indicates intermittent but recurring blacklisting activity, consistent with Tor exit node reputation management.
---
## Neighborhood Analysis
Subnet: 111.90.159.0/24
- Abuse Density: 1
- Classification: Mostly clean
- Total Siblings: 2
- Active Siblings: 2
- Threat Siblings: 2
Identified Neighbor:
- IP: 111.90.159.151
- Risk Score: 66/100
- Authority Score: 50/100
The /24 subnet shows concentrated threat activity with all identified siblings classified as threats, suggesting coordinated or shared infrastructure usage within this network block.
---
## Relationships Graph
Identified Connections:
- Multiple "Same Network" relationships to SHINJIRU-MY network entity
- 147+ relationship entries identified (primarily network-level associations)
---
## Recommended Actions
Immediate Actions:
1. Block 111.90.159.170 at perimeter firewall due to Tor exit node classification and active blacklist presence
2. Monitor 111.90.159.151 (neighbor IP, risk score 66) for correlated activity
3. Investigate TLS certificate mismatch (issuer ≠ subject) for potential C2 infrastructure
Firewall Rules:
```
iptables -A INPUT -s 111.90.159.0/24 -j DROP
# Or for targeted blocking:
iptables -A INPUT -s 111.90.159.170 -j DROP
```
Monitoring Recommendations:
- Track route stability for ASN 45839 (unstable routing observed)
- Monitor for new blacklist additions in the 111.90.159.0/24 subnet
- Alert on any new connections to the PTR hostname server1.kamon.la
---
## Conclusion
IP 111.90.159.170 represents a confirmed Tor exit node operating within a Malaysian ISP infrastructure. The combination of Tor exit indicators, active blacklist presence, certificate anomalies, and neighborhood threat density warrants defensive blocking at network perimeters. The unstable routing and high-risk sibling IPs suggest broader infrastructure abuse patterns within the /24 subnet that may require subnet-level policy consideration.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Shinjiru Technology Sdn Bhd administrator |
| ASN | AS45839 |
| Network Name | SHINJIRU-MY |
| CIDR Block | 111.90.128.0/19 |
| RIR | APNIC |
| Country | MY |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | server1.kamon.la |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | server1.kamon.la |
🔐 DNS Hygiene
| Hygiene Score | 0% (None) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 443 | https | tcp | — |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
CN=www.gcrjkld5xclt45qjiqa7.net was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.| SANs | None |
| Valid From | 2026-07-28T00:00:00+00:00 |
| Valid Until | 2026-08-23T23:59:59+00:00 (expired) |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 344 days |
🛡️ Public Network Snapshot
| Origin ASN | AS45839 |
| Network Prefix | 111.90.158.0/23 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 51% | 2 | 198 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 199 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-17 13:39:10 UTC |
| Last Seen | 2026-09-05 20:07:48 UTC |
| Profile Built | 2026-09-05 20:17:03 UTC |
| Data Freshness | Live |
| Signal Types | 28 |
| Total Observations | 242 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 111.90.159.170
Who owns the IP address 111.90.159.170?
111.90.159.170 is registered to Shinjiru Technology Sdn Bhd administrator. The address falls within the 111.90.128.0/19 network block. Registration is held at APNIC.
Where is 111.90.159.170 located?
Geolocation data places 111.90.159.170 in London. The local time zone is Asia/Kuala_Lumpur. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 111.90.159.170 malicious or safe?
111.90.159.170 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 111.90.159.170?
The reverse DNS (PTR) record for 111.90.159.170 is server1.kamon.la. This hostname is not forward-confirmed, so it should be treated as a weak signal.
What ports are open on 111.90.159.170?
Responsive ports observed on 111.90.159.170 include 80, 443. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.