IP Intelligence Briefing: 172.234.92.148
Date: 2026-06-07
---
**1. Risk Profile**
- Risk Score: Moderate (59/100)
- Threat Indicators:
- Identified as a Tor exit node (potential anonymity tool).
- Observed Tor exit indicators in DNS and TLS data.
- Network Role:
- Classified as a Tor exit node (not a traditional web server).
- Associated with Linode (cloud provider, ASN 63949).
- Geolocation:
- Registered to US (region: Osaka, city: Osaka).
- Geolocation data inconsistent (null coordinates).
---
**2. Observation History**
- Recent Activity (2026-06-07):
- Detected TLS handshakes (TLS 1.3, Letβs Encrypt certificate).
- Open ports: HTTP (80) and HTTPS (443).
- Server banner: nginx.
- No signs of recent compromises or persistent malicious activity.
- Temporal Trends:
- No significant changes in risk scores or network behavior.
- Threat persistence: 0 days (not flagged as persistently malicious).
---
**3. Relationships**
- Linked Entities:
- Linode (cloud provider, ASN 63949).
- Tor network (exit node, potential anonymity tool).
- Domain: `brokenbotnet.com` (DNS PTR: `tor-exit.brokenbotnet.com`).
- Certificates:
- TLS certificate issued to `tor-exit.brokenbotnet.com` (Letβs Encrypt).
---
**4. Neighborhood Analysis**
- Subnet: `172.234.92.148/24`
- Abuse Density:
- 0 abuse incidents reported in the subnet.
- 0 neighboring IPs identified (possibly isolated or limited data).
- Subnet Classification: "Mostly clean" with no inherited risk.
---
**5. Recommendations**
- Monitor Traffic:
- Track Tor exit node activity, as it may be used for illicit communications or data exfiltration.
- Firewall Rules:
- Consider blocking Tor exit nodes if not required for legitimate use.
- Verify Ownership:
- Confirm Linodeβs compliance with security practices for cloud-hosted Tor nodes.
---
Conclusion:
The IP is a Tor exit node associated with Linode, posing potential risks due to its anonymity capabilities. While no direct malicious activity is detected, its Tor association warrants further monitoring. No immediate action is required unless Tor usage is explicitly prohibited.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Linode |
| ASN | AS63949 |
| Network Name | β |
| CIDR Block | 172.234.80.0/20 |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | tor-exit.brokenbotnet.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | tor-exit.brokenbotnet.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | nginx |
| HTTP Title | β |
π TLS Certificate
| SANs | tor-exit.brokenbotnet.com |
| Valid From | 2026-06-07T11:07:52+00:00 |
| Valid Until | 2026-09-05T11:07:51+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
| Serial Number | 052471A77CAFDE27AD40D2E8749ACDFF3A65 |
| Thumbprint | 001544C307941FDBF824014872ECBA51A7469716 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 20% | 2 | 3 |
| services | 28% | 2 | 3 |
| ownership | 27% | 3 | 5 |
| reputation | 29% | 1 | 3 |
| geolocation | 34% | 2 | 3 |
| Overall | 27% | 12 | 21 |
| Data Coherence | Mostly Consistent (85%) β 1 contradiction(s) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-22 13:35:43 UTC |
| Last Seen | 2026-06-28 19:25:49 UTC |
| Profile Built | 2026-06-29 01:27:47 UTC |
| Data Freshness | Live |
| Signal Types | 30 |
| Total Observations | 56 |
Full dossier details are available via our API.