IPDebrief

147.90.235.17

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

## IP Intelligence Briefing: 147.90.235.17

Classification: HIGH RISK TOR EXIT NODE

Risk Score: 70/100

Date: 2026-06-21

Executive Summary

IP address 147.90.235.17 operates as a Tor exit node registered to Fourplex Telecom LLC (ASN: 27284). The IP demonstrates high-risk characteristics with Tor exit node indicators, single-HTTP service exposure, and membership in a high-abuse-density subnet (0.9167). Geographic validation failures indicate potential spoofing. Immediate defensive measures recommended.

---

Network Profile

AttributeValue
**Organization**Fourplex Telecom LLC abuse handling
**Netname**FOURPL-147-90-234-0
**CIDR Block**147.90.234.0/23
**ASN**27284
**Network Role**Tor Exit Nodes / Residential
**Geolocation**NL (Netherlands) - *Invalidated*
**Open Services**TCP/80 (HTTP)

Threat Indicators

Neighborhood Analysis (147.90.235.0/24)

The /24 subnet exhibits critical abuse concentration:

High-Risk Neighbors Include:

Historical Observations

37 total observations recorded. Recent activity shows:

---

Recommended Actions

Immediate (High Severity):

1. Block at perimeter firewall

```bash

iptables -A INPUT -s 147.90.235.17 -j DROP

nft add rule inet filter input ip saddr 147.90.235.17 drop

```

Monitoring Enhancements:

2. Increase logging verbosity for all traffic from 147.90.235.0/24 subnet

3. Enable enhanced verification for anonymous traffic patterns

4. Review recent activity from this IP for potential abuse campaigns

Application-Level Controls:

```nginx

nginx: deny 147.90.235.17;

Cloudflare WAF: Block IP 147.90.235.17 (Risk: 70)

AWS WAF: Add 147.90.235.17/32 to block list

```

---

Intelligence Notes

Recommended Severity: HIGH

Action Priority: Immediate

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡³πŸ‡± Netherlands
RegionNew York
CityNew York
TimezoneEurope/Amsterdam
Latitude52.13
Longitude5.29

🏒 Ownership & Registration

OrganizationFourplex Telecom LLC abuse handling
ASNAS27284
Network NameFOURPL-147-90-234-0
CIDR Block147.90.234.0/23
RIRARIN
CountryUS
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)

πŸ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeSingle-Service Host
Network TierTier 3 β€” Basic operator with some routing infrastructure
Tor

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpβ€”
Closed Ports22, 25, 443, 3389, 8080, 8443 (1 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
34%
24
routing
29%
23
services
30%
23
ownership
43%
36
reputation
30%
13
geolocation
35%
23
Overall34%1222
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceMixed Signals (60%) β€” 2 contradiction(s)
AttributionVery Low (20%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Claimed geolocation contradicts RTT physics measurement
⚠ Geo sources disagree on country: US, NL

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-27 19:00:41 UTC
Last Seen2026-06-26 21:06:53 UTC
Profile Built2026-06-27 19:15:01 UTC
Data FreshnessLive
Signal Types25
Total Observations52
πŸ” 25 signal types Β· 52 observations collected
This report is generated from 25+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.