IPDebrief

173.255.198.243

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# THREAT INTELLIGENCE BRIEFING

IP Address: 173.255.198.243/32

Classification: Moderate Risk Tor Exit Node

Report Generated: Current Session

Data Sources: IPDebrief Intelligence Platform

---

## EXECUTIVE SUMMARY

IP 173.255.198.243 is a Linode-hosted Tor exit node located in Richardson, Texas (US). The address exhibits Tor exit node characteristics and has been observed in threat feeds. The IP maintains moderate risk posture with a risk score of 49/100. Network neighborhood analysis indicates low abuse density (0.0) within the /24 subnet, with one sibling IP (173.255.198.110) showing zero risk.

---

## OWNERSHIP & INFRASTRUCTURE

AttributeValue
**ASN**63949
**Organization**Linode
**Registry**ARIN
**CIDR Block**173.255.192.0/20
**Geolocation**US, TX, Richardson (2500km accuracy radius)
**Control Plane**Route stable, DNSSEC valid

The IP resolves to hostname `brutus.relaymagic.org` via forward DNS. Network classification identifies this address as a Tor exit node with HTTPS service on port 443. TLS certificate indicates issuer CN=www.bwiu7lg3cgbu.com with subject CN=www.q3o6wunve7eqdrk.net.

---

## THREAT ASSESSMENT

Current Risk Profile

Network Role

---

## OBSERVATION HISTORY

Total Observations: 51 signals

Recent Trend: Stable low-risk signals

Observation timeline shows consistent "Minimal" risk labels across the past week:

No evidence of escalating malicious activity or persistent threat behavior. Threat observation count: 1.

---

## RELATIONSHIP MAPPING

Total Relationships: 344 entities

Primary Associations:

The IP maintains standard Linode infrastructure relationships with DNS-based hostname associations.

---

## NEIGHBORHOOD ANALYSIS

Subnet: 173.255.198.243/24

Abuse Density: 0.0 (Low)

Classification: Mostly Clean

MetricValue
**Total Siblings**1
**Active Siblings**1
**Threat Siblings**0
**High Risk Neighbors**0
**Medium Risk Neighbors**0
**Low Risk Neighbors**1 (173.255.198.110, risk score 0)

The /24 subnet demonstrates minimal abuse activity, inherited risk score of 2, and no correlation with known malicious campaigns.

---

## GEOGRAPHIC VALIDATION

Location Confidence: GeoPlausible = false

RTT Anomaly: 55ms minimum observed vs 159.6ms minimum expected for 7979km distance

Probe Count: 5

Distance Violation: RTT 55.0ms < minimum possible 159.6ms for 7979km

Geolocation data shows 2500km accuracy radius with RTT anomalies suggesting potential location spoofing or proxy usage.

---

## SECURITY RECOMMENDATIONS

Immediate Actions

1. Monitor Tor Traffic: Implement egress filtering for Tor exit node traffic if policy prohibits

2. DNSBL Verification: Review blacklist status across 8 DNSBL services

3. Connection Logging: Enable logging for connections from this IP to track usage patterns

Firewall Rules (Recommended)

SOC Analyst Notes

---

## CONCLUSION

IP 173.255.198.243 is a Linode-hosted Tor exit node with moderate risk classification. The address exhibits expected Tor infrastructure characteristics without evidence of active malicious campaigns. Network neighborhood analysis supports a clean operational environment. SOC teams should monitor per organizational policy regarding Tor traffic but may permit connectivity with appropriate logging and monitoring controls.

Risk Rating: Moderate (49/100)

Action Required: Monitor/Allow based on policy

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionTX
CityRichardson
Timezoneβ€”
Latitude32.95
Longitude-96.73

🏒 Ownership & Registration

OrganizationLinode
ASNAS63949
Network Nameβ€”
CIDR Block173.255.192.0/20
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRbrutus.relaymagic.org
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamesbrutus.relaymagic.org

πŸ” DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierUnknown β€” Insufficient routing data to classify
No specific classification

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
443httpstcpβ€”
Closed Ports22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
CN=www.q3o6wunve7eqdrk.net
Issued by CN=www.bwiu7lg3cgbu.com
Self-signed: No
SANsNone
Valid From2026-05-20T00:00:00+00:00
Valid Until2026-07-19T23:59:59+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period60 days
Serial Number00EEC9D0979650742F
ThumbprintFD777E898B3269E6937332AAB1F9A398817E8403

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
26%
24
routing
20%
23
services
30%
23
ownership
19%
34
reputation
28%
13
geolocation
33%
23
Overall26%1220
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) β€” 1 contradiction(s)
AttributionModerate (55%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Claimed geolocation contradicts RTT physics measurement

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-22 13:35:38 UTC
Last Seen2026-06-28 19:11:13 UTC
Profile Built2026-06-29 07:14:44 UTC
Data FreshnessLive
Signal Types29
Total Observations53
πŸ” 29 signal types Β· 53 observations collected
This report is generated from 29+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.