IPDebrief

147.161.3.20

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 147.161.3.20/32

Classification: Moderate Risk Tor Exit Node

Date of Analysis: 2026-07-31

Prepared by: IPDebrief Threat Intelligence

---

## Executive Summary

IP address 147.161.3.20 is a confirmed Tor exit node operating from the Srvnet_LTD network (ASN 399486). The IP presents a moderate risk profile (score: 59/100) with active Tor exit node indicators and one confirmed blacklist listing. The IP is geolocated to Amsterdam, CZ (Prague timezone) and maintains a stable ownership history with no persistent malicious behavior observed.

---

## Threat Indicators

The IP has been flagged by threat feeds for Tor exit node activity. While not classified as a known attacker or spam source, Tor exit nodes present elevated risk for anonymized malicious traffic and should be treated as suspicious for inbound connections.

---

## Network Context

Ownership:

Geolocation:

Network Stability:

---

## Neighborhood Analysis

The /24 subnet (147.161.3.0/24) contains 5 active sibling IPs with the following risk distribution:

Neighbor IPs:

IP AddressRisk ScoreAuthority Score
147.161.3.256650
147.161.3.315950
147.161.3.327050
147.161.3.335950

Subnet abuse density indicates moderate activity, with all siblings presenting medium to high risk scores. The subnet should be monitored collectively.

---

## Service & Port Analysis

The IP does not expose any active services, which is consistent with Tor exit node behavior that typically routes traffic without hosting additional services.

---

## Historical Observations

Observation Count: 45 signals recorded

Recent Activity (2026-07-31):

The IP shows persistent Tor exit node activity without escalation to known attacker behavior.

---

## Recommended Actions

Firewall Rules:

```

# Block Tor exit node traffic (recommended)

iptables -A INPUT -s 147.161.3.20/32 -j DROP

```

Monitoring:

Assessment: This IP should be blocked for inbound connections to prevent potential abuse through Tor anonymity. The moderate risk score combined with Tor exit node classification warrants defensive treatment.

---

Report Generated: IPDebrief Intelligence Platform

Data Sources: Real-time threat feeds, geolocation databases, historical signal logs

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇨🇿 Czechia
RegionNH
CityAmsterdam
TimezoneEurope/Prague
Latitude49.82
Longitude15.47

🏢 Ownership & Registration

Organizationnetutils-mnt
ASNAS399486
Network NameSrvnet_LTD
CIDR Block147.161.3.0/24
RIRARIN
CountryEU
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)

🔐 DNS Hygiene

Hygiene Score0% (None)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECNot signed
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeSingle-Service Host
Network TierUnknown — Insufficient routing data to classify
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
22sshtcpBanner detected
Closed Ports25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned)
Server—
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS399486
Network Prefix147.161.3.0/24
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
29%
24
routing
27%
23
services
37%
23
ownership
30%
34
reputation
26%
13
geolocation
32%
23
Overall30%1220
Coverage: 6/6 dimensions · Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

📅 Observation Timeline 🔄 Live

First Seen2026-07-16 14:01:30 UTC
Last Seen2026-08-04 21:35:21 UTC
Profile Built2026-09-04 10:20:41 UTC
Data FreshnessLive
Signal Types25
Total Observations219
🔍 25 signal types · 219 observations collected
This report is generated from 25+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 147.161.3.20

Who owns the IP address 147.161.3.20?

147.161.3.20 is registered to netutils-mnt. The address falls within the 147.161.3.0/24 network block. Registration is held at ARIN.

Where is 147.161.3.20 located?

Geolocation data places 147.161.3.20 in Amsterdam, NH, Czechia. The local time zone is Europe/Prague. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 147.161.3.20 malicious or safe?

147.161.3.20 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.

What ports are open on 147.161.3.20?

Responsive ports observed on 147.161.3.20 include 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.

🏘️ Related IP Addresses

Nearby addresses in 147.161.3.0/24

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.