IPDebrief

158.220.112.15

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

IP INTELLIGENCE BRIEFING: 158.220.112.15/32

Classification: TOR EXIT NODE - MODERATE RISK

Executive Summary

IP 158.220.112.15 is classified as a Tor exit node with a risk score of 49/100. The address is not currently flagged as a known attacker or spam source, but the Tor exit node designation combined with one blacklist entry warrants monitoring. No open services were detected on this IP.

---

Threat Profile

Geolocation & Network Ownership

DNS & Infrastructure

---

Observation History (57 total signals)

The IP shows consistent observation patterns with recent activity concentrated in early June 2026. Signal types include basic routing and network classification observations. Operator scores remain stable at approximately 0.26. No significant degradation or escalation in threat posture observed over the monitoring period.

---

Neighborhood Analysis (158.220.112.0/24)

The /24 subnet demonstrates low overall abuse density with one identified threat sibling, indicating localized but contained risk within the network.

---

Relationship Graph (440 relationships)

---

Recommended Security Actions

Severity: Medium

Access Control:

Firewall Recommendations:

*iptables:*

```

iptables -A INPUT -s 158.220.112.15 -j DROP

```

*nftables:*

```

nft add rule inet filter input ip saddr 158.220.112.15 drop

```

*nginx:*

```

deny 158.220.112.15;

```

*pfSense:*

```

158.220.112.15/32

```

*Cloudflare WAF:*

```json

{"description":"Block 158.220.112.15 โ€” IPDebrief risk score 49","action":"block","filter":{"expression":"ip.src eq 158.220.112.15"}}

```

*AWS WAF:*

```json

{"Addresses":["158.220.112.15/32"],"Description":"IPDebrief risk 49"}

```

---

Intelligence Assessment

This IP address functions as a Tor exit node, which is commonly leveraged by threat actors to mask source IP addresses during attacks. While the IP is not currently flagged as an active attacker or spam source, the combination of Tor exit node status and blacklist presence suggests elevated risk. The absence of open services is consistent with many Tor exit nodes that relay traffic without hosting applications.

Recommendation: Block traffic from this IP at the perimeter firewall, particularly if your organization handles sensitive data or provides customer-facing services. Monitor for any changes in threat indicators in the subsequent 7-14 days.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฉ๐Ÿ‡ช Germany
RegionGrand Est
CityLauterbourg
TimezoneEurope/Berlin
Latitude51.17
Longitude10.45

๐Ÿข Ownership & Registration

OrganizationJohannes Selg
ASNAS51167
Network Nameโ€”
CIDR Block158.220.112.0/20
RIRARIN
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRvmi2615704.contaboserver.net
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnamesvmi2615704.contaboserver.net

๐Ÿ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierTier 3 โ€” Basic operator with some routing infrastructure
Tor

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
26%
24
routing
17%
23
services
12%
22
ownership
30%
38
reputation
28%
13
geolocation
24%
23
Overall23%1223
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-22 13:35:51 UTC
Last Seen2026-06-28 19:33:27 UTC
Profile Built2026-06-29 07:37:00 UTC
Data FreshnessLive
Signal Types29
Total Observations58
๐Ÿ” 29 signal types ยท 58 observations collected
This report is generated from 29+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.