IP Intelligence Briefing: 152.89.39.187
Date: 2026-06-10
---
**1. Risk Profile**
- Overall Risk Score: Low Risk (25/100)
- Threat Indicators: No malicious activity detected (no blacklists, campaigns, or abuse reports).
- Network Role: Tor Exit Node (classified as "Provider" in network infrastructure).
- Geolocation: Frankfurt, Germany (DE).
---
**2. Ownership & Infrastructure**
- ASN: 42807 (Administrative Contact).
- ISP: ARIN-regulated network (arin).
- Services:
- Open ports: HTTP (80), HTTPS (443), SSH (22).
- SSH banner: `SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13`.
- Control Plane:
- BGP prefix: `152.89.36.0/22`.
- AS path: `2914 9121 42807`.
- DNSSEC valid, route stability confirmed.
---
**3. Threat & Observation History**
- Recent Signals (30 days):
- No high-severity threats detected.
- Low-confidence observations (e.g., DNSSEC validity, route stability).
- No correlation with known malicious campaigns or domains.
- Historical Trends: Stable network behavior with no persistent malicious activity.
---
**4. Network Relationships**
- Linked Networks: Multiple entries tied to `TR-CIZGI-20190123` (possible typo or internal network identifier).
- Subnet: `152.89.39.187/24` (no malicious neighbors detected).
- Abuse Density: 0 (clean subnet).
---
**5. Recommendations**
- Monitor: Track network relationships linked to `TR-CIZGI-20190123` for anomalies.
- Verify: Confirm Tor exit node activity aligns with expected traffic patterns.
- Baseline: Use historical data to establish normal behavior for this IP.
Conclusion: This IP appears benign, but its association with Tor and unclear network relationships warrants further investigation. No immediate action required, but continuous monitoring is advised.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Administrative Contact |
| ASN | AS42807 |
| Network Name | โ |
| CIDR Block | 152.89.36.0/22 |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13 |
๐ TLS Certificate
| SANs | None |
| Valid From | 2026-05-11T00:00:00+00:00 |
| Valid Until | 2026-07-27T00:00:00+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 77 days |
| Serial Number | 656AA835C8D8156D |
| Thumbprint | 751E5F07DABCA0653EA5887EF13C0C0F42D5F151 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 57% | 2 | 10 |
| routing | 27% | 2 | 3 |
| services | 32% | 2 | 3 |
| ownership | 41% | 3 | 10 |
| reputation | 18% | 1 | 2 |
| geolocation | 21% | 2 | 2 |
| Overall | 33% | 12 | 30 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-22 13:35:51 UTC |
| Last Seen | 2026-06-26 21:06:52 UTC |
| Profile Built | 2026-06-27 16:00:29 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 66 |
Full dossier details are available via our API.