# IPDEBRIEF INTELLIGENCE BRIEFING
Target: 144.31.237.91/32
Date: Analysis conducted
Classification: High Risk
---
## EXECUTIVE SUMMARY
The IP address 144.31.237.91 was classified as High Risk (70/100) during analysis. The address is registered to ETERNITY-NETWORK (ASN 212743) within the 144.31.237.0/24 block and demonstrated Tor exit node indicators. The IP maintains a firewalled posture with no open services observed.
---
## OWNERSHIP AND REGISTRATION
- ASN: 212743
- Organization: Abuse contact role object / ETERNITY-NETWORK
- RIR: ARIN
- CIDR Block: 144.31.237.0/24
- Registration Date: Not publicly disclosed
- Abuse Contact: abuse@eternitycloud.org (via RDAP)
---
## GEOLOCATION
- Country: United States (US)
- Region: US-NY
- City: New York
- Timezone: America/New_York
- Geographic Validation: GeoPlausible confirmed; ICMP validation blocked
---
## THREAT PROFILE
- Reputation: High Risk
- Risk Score: 70/100
- Tor Exit Node: Yes
- Blacklist Status: Listed on 1 blacklist; 3 DNSBL entries across 8 total lists
- Threat Indicators: Tor exit indicators observed
- Known Campaigns: None correlated
---
## NETWORK CHARACTERISTICS
- Network Role: Tor Exit Nodes
- Infrastructure Type: Unknown
- Open Services: None (firewalled / no services)
- DNS Resolution: No PTR hostnames; no forward resolution
- BGP Routing: Origin ASN 212743; BGP prefix 144.31.237.0/24
- Route Stability: Route not stable
- RPKI State: Not verified
- Traceroute: 27 hops to destination (7 timed out); transit via Comcast networks
---
## TEMPORAL ANALYSIS
- Observation Count: 1 threat observation
- Threat Persistence: 0 days
- Persistent Malicious: No
- Ownership Changes: 0
- Recent Signals: 20 observations recorded between 2026-07-23
---
## SUBNET NEIGHBORHOOD (144.31.237.0/24)
- Subnet Classification: Clean
- Abuse Density: 0%
- Total Siblings: 1
- Active Siblings: 0
- Threat Siblings: 0
- High/Medium/Low Risk Neighbors: None
---
## RELATIONSHIPS
- Connected Networks: ETERNITY-NETWORK (2 relationships)
- Related Entities: None beyond network affiliation
- Associated Certificates: None
---
## OBSERVATION HISTORY
Recent signals indicate:
- Operator score: Minimal (0.1304)
- Multiple ownership and routing signals observed
- Geographic data inconsistencies noted (NL vs US registration)
- Confidence levels varied (0.30–0.95) across observations
---
## RECOMMENDED ACTIONS
Access Control
Action: Consider enhanced verification for anonymous traffic
Severity: Medium
Rationale: Tor exit indicators observed; traffic may bypass standard authentication mechanisms
Monitoring
Action: Increase logging verbosity and review recent activity from this IP
Severity: High
Rationale: Elevated risk score (70/100) warrants enhanced visibility
Firewall Implementation
- iptables: `iptables -A INPUT -s 144.31.237.91 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 144.31.237.91 drop`
- nginx: `deny 144.31.237.91;`
- pfSense: `144.31.237.91/32` (block rule)
- Cloudflare WAF: Block with expression `ip.src eq 144.31.237.91`
- AWS WAF: Add address 144.31.237.91/32 to block list
---
## ANALYST NOTES
The IP address 144.31.237.91 is registered to ETERNITY-NETWORK but demonstrates Tor exit node behavior. Despite being geolocated to New York, US, some historical observations indicated NL (Netherlands). The subnet shows zero abuse density with no sibling threats. The firewalled state with no open services suggests the IP may serve as an anonymous relay rather than a hosting endpoint. Enhanced logging and monitoring are recommended due to the High Risk classification and Tor exit node characteristics.
---
END OF BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Abuse contact role object |
| ASN | AS212743 |
| Network Name | ETERNITY-NETWORK |
| CIDR Block | 144.31.237.0/24 |
| RIR | ARIN |
| Country | NL |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 89 days |
🛡️ Public Network Snapshot
| Origin ASN | AS212743 |
| Network Prefix | 144.31.237.0/24 |
| Route mapping | Found |
| HSTS | Not detected |
| CSP | Not detected |
| HTTP/2 | Enabled |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 6 |
| routing | 8% | 1 | 1 |
| services | 28% | 2 | 4 |
| ownership | 23% | 2 | 4 |
| reputation | 26% | 1 | 5 |
| geolocation | 17% | 2 | 3 |
| Overall | 23% | 10 | 23 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-12 02:15:15 UTC |
| Last Seen | 2026-09-04 13:03:19 UTC |
| Profile Built | 2026-09-04 13:09:45 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 34 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 144.31.237.91
Who owns the IP address 144.31.237.91?
144.31.237.91 is registered to Abuse contact role object. The address falls within the 144.31.237.0/24 network block. Registration is held at ARIN.
Where is 144.31.237.91 located?
Geolocation data places 144.31.237.91 in Eygelshoven, Limburg, Netherlands. The local time zone is Europe/Amsterdam. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 144.31.237.91 malicious or safe?
144.31.237.91 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
Is 144.31.237.91 a VPN, proxy, or data center address?
144.31.237.91 is classified as the Tor network based on network ownership and behavioural analysis.