# IPDEBRIEF INTELLIGENCE BRIEFING
Target: 167.179.117.50/32
Classification: TOR EXIT NODE - MODERATE RISK
Date: Current
---
## EXECUTIVE SUMMARY
IP address 167.179.117.50 operates as a Tor exit node within Japan, presenting moderate risk (score: 59). The IP belongs to IRT-CHOOPALLC-AP (ASN 20473) on the TYO_VULTR_CUST network infrastructure. Current operational status indicates no open services; the endpoint is firewalled. A single blacklist listing and one threat-adjacent sibling IP are documented.
---
## TECHNICAL PROFILE
| Attribute | Value |
|---|---|
| **Risk Score** | 59 (Moderate) |
| **ASN** | 20473 (IRT-CHOOPALLC-AP) |
| **Organization** | IRT-CHOOPALLC-AP |
| **Network Name** | TYO_VULTR_CUST |
| **CIDR Block** | 167.179.96.0/19 |
| **Location** | Japan (JP), Heiwajima |
| **PTR Hostname** | io6b.com |
| **Network Role** | Tor Exit Nodes |
| **DNSBL Listed** | 1 of 8 lists |
| **Services** | None (Firewalled) |
---
## THREAT INDICATORS
- Tor Exit Node: Confirmed active Tor exit node operation
- Blacklist Presence: 1 blacklist listing detected
- Reputation: No known attacker or spam source classification
- Campaign Correlation: None identified
---
## NEIGHBORHOOD CONTEXT
Subnet 167.179.117.50/24 shows low abuse density (0) with classification "mostly_clean." One active threat sibling IP identified within the subnet. No additional neighbor relationships detected. The IP is part of a larger 223-entity relationship cluster, primarily mapped to TYO_VULTR_CUST network infrastructure.
---
## OBSERVATION HISTORY
62 total signals observed. Recent monitoring (June 20, 2026) shows consistent operator scoring at 0.3913 ("Basic" classification) with route stability maintained. No significant temporal threat escalation patterns detected.
---
## RECOMMENDED ACTIONS
For SOC/Network Defense:
1. Monitor inbound connections from this Tor exit node for data exfiltration or command-and-control activity
2. Implement connection rate limiting for traffic originating from 167.179.117.0/24 subnet
3. Review any recent outbound connections to this IP for potential compromise indicators
4. Consider blocking or monitoring based on organizational policy for Tor exit node traffic
Firewall Rule Recommendation:
```
# Monitor Tor traffic from this exit node
iptables -A INPUT -s 167.179.117.50 -j LOG --log-prefix "TOR_EXIT:"
# Or block if policy prohibits
# iptables -A INPUT -s 167.179.117.50 -j DROP
```
---
## ANALYST NOTES
This IP represents legitimate Tor infrastructure rather than direct malicious activity. The primary concern is its use as an anonymization endpoint, which may be exploited by adversaries for C2 or exfiltration. The absence of open services reduces direct exploitation risk, but traffic analysis remains warranted.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-CHOOPALLC-AP |
| ASN | AS20473 |
| Network Name | TYO_VULTR_CUST |
| CIDR Block | 167.179.96.0/19 |
| RIR | ARIN |
| Country | JP |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | io6b.com |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | io6b.com |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 27% | 2 | 3 |
| services | 19% | 2 | 2 |
| ownership | 35% | 3 | 8 |
| reputation | 25% | 1 | 3 |
| geolocation | 24% | 2 | 3 |
| Overall | 27% | 12 | 23 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-29 05:53:48 UTC |
| Last Seen | 2026-06-29 06:04:57 UTC |
| Profile Built | 2026-06-29 06:12:31 UTC |
| Data Freshness | Live |
| Signal Types | 30 |
| Total Observations | 57 |
Full dossier details are available via our API.