IPDebrief

176.121.81.51

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

IP Intelligence Briefing: 176.121.81.51

Date: 2026-06-09

---

**1. Risk Profile**

- Flagged as a Tor exit node (blacklisted in 1 source).

- No known malicious campaigns or spam activity.

- Country: Poland (PL)

- City: Wroclaw

- ISP: AMSNET-MNT (AS59444)

---

**2. Observation History**

- Observed as a Tor exit node in the last 30 days.

- No persistent malicious behavior or threat persistence.

- BGP route stability: Unstable (route changes detected).

- No DNSSEC violations or CAA misconfigurations.

---

**3. Relationships**

- Linked to AMSNET-PL (AS59444) via the same /22 subnet (176.121.80.0/22).

- No direct connections to known malicious domains or organizations.

- Resolves to host-176-121-81-51.amsnet.pl.

- SPF and DMARC records present but not validated.

---

**4. Neighborhood Analysis**

- 0 active neighbors detected.

- Subnet abuse density: 0% (clean classification).

---

**5. Key Findings**

---

**6. Recommendations**

1. Block Tor Exit Nodes: If not required, block traffic from this IP to mitigate potential anonymized attacks.

2. Monitor Network Activity: Track changes in BGP routes or DNS behavior for anomalies.

3. Verify Ownership: Confirm AMSNET-MNTโ€™s compliance with security best practices for Tor infrastructure.

4. Check Subnet: Investigate the 176.121.80.0/22 subnet for additional Tor-related IPs.

---

End of Briefing

*Generated by IPDebrief for SOC operational use.*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ต๐Ÿ‡ฑ Poland
Region02
CityWroclaw
TimezoneEurope/Warsaw
Latitude51.92
Longitude19.15

๐Ÿข Ownership & Registration

OrganizationAMSNET-MNT
ASNAS59444
Network Nameโ€”
CIDR Block176.121.80.0/22
RIRRIPE
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRhost-176-121-81-51.amsnet.pl
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnameshost-176-121-81-51.amsnet.pl

๐Ÿ” DNS Hygiene

Hygiene Score60% (Good)
SPFPresent
DMARCPresent
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeSingle-Service Host
Network TierTier 3 โ€” Basic operator with some routing infrastructure
Tor

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
22sshtcp
Closed Ports25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”
SSH VersionSSH-2.0-OpenSSH_7.4

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
45%
28
routing
27%
23
services
15%
22
ownership
42%
310
reputation
26%
13
geolocation
32%
23
Overall31%1229
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-22 13:35:47 UTC
Last Seen2026-06-26 21:06:52 UTC
Profile Built2026-06-27 15:52:35 UTC
Data FreshnessLive
Signal Types30
Total Observations68
๐Ÿ” 30 signal types ยท 68 observations collected
This report is generated from 30+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.