IP INTELLIGENCE BRIEFING: 158.220.112.15/32
Classification: TOR EXIT NODE - MODERATE RISK
Executive Summary
IP 158.220.112.15 is classified as a Tor exit node with a risk score of 49/100. The address is not currently flagged as a known attacker or spam source, but the Tor exit node designation combined with one blacklist entry warrants monitoring. No open services were detected on this IP.
---
Threat Profile
- Risk Score: 49 (Moderate Risk)
- Network Classification: Tor Exit Nodes
- Threat Indicators: Tor exit indicators observed
- Blacklist Status: 1 blacklist entry
- Known Attacker: No
- Spam Source: No
Geolocation & Network Ownership
- Country/Region: Germany (DE), Grand Est region
- City: Lauterbourg
- ASN: 51167
- Organization: Johannes Selg
- RIR: ARIN
- BGP Prefix: 158.220.112.0/20
- Route Stability: Stable (no route changes in 30 days)
DNS & Infrastructure
- PTR Hostname: vmi2615704.contaboserver.net
- Forward Resolution: Confirmed (contaboserver.net)
- Open Ports: None detected
- TLS Certificate: None
- HTTP Services: None detected
---
Observation History (57 total signals)
The IP shows consistent observation patterns with recent activity concentrated in early June 2026. Signal types include basic routing and network classification observations. Operator scores remain stable at approximately 0.26. No significant degradation or escalation in threat posture observed over the monitoring period.
---
Neighborhood Analysis (158.220.112.0/24)
- Abuse Density: 1 (Low)
- Subnet Classification: Mostly Clean
- Inherited Risk: 2
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 1
The /24 subnet demonstrates low overall abuse density with one identified threat sibling, indicating localized but contained risk within the network.
---
Relationship Graph (440 relationships)
- Network Associations: Multiple links to network identifier TT-20230331
- DNS Associations: vmi2615704.contaboserver.net
- Infrastructure Type: Virtual machine instance (contaboserver.net hosting)
---
Recommended Security Actions
Severity: Medium
Access Control:
- Consider enhanced verification for anonymous traffic originating from this IP
- The Tor exit node status requires additional scrutiny for incoming connections
Firewall Recommendations:
*iptables:*
```
iptables -A INPUT -s 158.220.112.15 -j DROP
```
*nftables:*
```
nft add rule inet filter input ip saddr 158.220.112.15 drop
```
*nginx:*
```
deny 158.220.112.15;
```
*pfSense:*
```
158.220.112.15/32
```
*Cloudflare WAF:*
```json
{"description":"Block 158.220.112.15 โ IPDebrief risk score 49","action":"block","filter":{"expression":"ip.src eq 158.220.112.15"}}
```
*AWS WAF:*
```json
{"Addresses":["158.220.112.15/32"],"Description":"IPDebrief risk 49"}
```
---
Intelligence Assessment
This IP address functions as a Tor exit node, which is commonly leveraged by threat actors to mask source IP addresses during attacks. While the IP is not currently flagged as an active attacker or spam source, the combination of Tor exit node status and blacklist presence suggests elevated risk. The absence of open services is consistent with many Tor exit nodes that relay traffic without hosting applications.
Recommendation: Block traffic from this IP at the perimeter firewall, particularly if your organization handles sensitive data or provides customer-facing services. Monitor for any changes in threat indicators in the subsequent 7-14 days.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS51167 |
| Network Name | โ |
| CIDR Block | 158.220.112.0/20 |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vmi2615704.contaboserver.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | vmi2615704.contaboserver.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 17% | 2 | 3 |
| services | 12% | 2 | 2 |
| ownership | 30% | 3 | 8 |
| reputation | 28% | 1 | 3 |
| geolocation | 24% | 2 | 3 |
| Overall | 23% | 12 | 23 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-22 13:35:51 UTC |
| Last Seen | 2026-06-28 19:33:27 UTC |
| Profile Built | 2026-06-29 07:37:00 UTC |
| Data Freshness | Live |
| Signal Types | 29 |
| Total Observations | 58 |
Full dossier details are available via our API.