IP Intelligence Briefing: 171.25.193.39
Date: 2026-06-09
---
**1. Core Profile**
- Risk Score: Moderate (40/100)
- Network Role: Tor Exit Node (provider: DFRI-MNT, ASN: 198093)
- Geolocation:
- Country: Sweden (SE)
- City: London (latitude: 60.13, longitude: 18.64)
- Note: Geolocation appears inconsistent with Tor exit node operational patterns (Tor nodes are typically anonymized).
- Threat Indicators:
- No known malicious activity, spam, or blacklist associations.
- No active services or TLS certificates detected.
---
**2. Observation History**
- Recent Activity:
- Identified as a Tor exit node (June 9, 2026).
- Traceroute shows transit through Comcast and Cogent networks.
- No persistent threat signals (zero threat observations in 30-day window).
---
**3. Network Relationships**
- DNS Associations:
- Linked to `tor-exit-read-me.dfri.se` (hostname).
- SPF/DNSSEC validation confirmed.
- Network Context:
- Part of the `SE-TORNET` subnet (171.25.193.0/24).
- No direct connections to known malicious networks.
---
**4. Subnet Neighborhood**
- Subnet: 171.25.193.0/24 (20 total IPs).
- Risk Distribution:
- 19 IPs with "medium" risk (40β66 score), 0 high-risk.
- Notable neighbors:
- 171.25.193.38 (70/100), 171.25.193.46 (40/100), 171.25.193.235 (66/100).
- Abuse Density: Low (0/100).
---
**5. Threat Context**
- Tor Exit Node Risks:
- Exit nodes can relay malicious traffic (e.g., malware, phishing).
- Anonymity may mask attacker origins.
- Geolocation Anomaly:
- Sweden (SE) vs. London (UK) discrepancy warrants further validation.
---
**6. Recommendations**
- Monitor Traffic:
- Block or monitor traffic originating from this IP, given its Tor exit node status.
- Investigate Neighbors:
- Focus on high-risk neighbors (e.g., 171.25.193.38, 171.25.193.235).
- Verify Geolocation:
- Cross-check IP metadata with additional geolocation sources.
- Enable Logging:
- Capture DNS requests to `tor-exit-read-me.dfri.se` for deeper analysis.
Conclusion: While no direct threats are detected, the IPβs association with Tor exit infrastructure and inconsistent geolocation require vigilance. Prioritize monitoring and neighbor analysis to mitigate potential indirect risks.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DFRI-MNT |
| ASN | AS198093 |
| Network Name | β |
| CIDR Block | β |
| RIR | APNIC |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | tor-exit-read-me.dfri.se |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | tor-exit-read-me.dfri.se |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
CN=www.jtyrhsn4.net was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.| SANs | None |
| Valid From | 2026-05-23T00:00:00+00:00 |
| Valid Until | 2026-06-13T00:00:00+00:00 (expired) |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 21 days |
| Serial Number | 00FE2B0CD4D0F06765 |
| Thumbprint | 36BA99CA36F5031FEC67A5001D60650A1FB6F60D |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 15% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 28% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 18% | 1 | 2 |
| geolocation | 19% | 2 | 2 |
| Overall | 19% | 10 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-22 13:35:41 UTC |
| Last Seen | 2026-06-26 21:06:49 UTC |
| Profile Built | 2026-06-27 17:38:32 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 49 |
Full dossier details are available via our API.