IPDebrief

178.218.144.64

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

IP Intelligence Briefing: 178.218.144.64

Date: 2026-06-16

---

**1. Core Profile**

- Open ports: SSH (22/TCP), HTTPS-alt (8443/TCP)

- TLS Certificate: Issued to `www.lbvc4e6x3uemnx.com`, SANs unspecified

- No HTTP server banner detected

---

**2. Threat Indicators**

- 1 DNSBL listing (potential spam or malicious activity)

- No known attacker campaigns or spam sources

---

**3. Observation History**

- Tor exit node activity detected (1 observation)

- Minimal risk score (0.13) from 2349 signal type

- TLS certificate and SSH banner scans (no critical vulnerabilities)

- ICMP validation failed (potential firewall blocking)

---

**4. Network Relationships**

- Same network: `IT-LowHosting-Services` (repeated 35+ times)

- Subnet: 178.218.144.0/24 (4 neighbors analyzed)

- DNS: `178.218.144.64.lowhosting.org` (PTR record confirmed)

---

**5. Neighborhood Analysis**

- Total IPs: 256

- Active Neighbors: 2 (high/medium risk)

- Risk Distribution:

- 4 medium-risk neighbors (scores: 40โ€“59)

- 1 high-risk neighbor (score: 59)

- Abuse Density: 40% (mostly clean, but elevated risk)

---

**6. Recommended Actions**

- Implement firewall rules to restrict traffic from 178.218.144.64 to Tor networks.

- Audit SSH logs for unauthorized access attempts on port 22.

- Focus on neighbors with medium/high risk (e.g., 178.218.144.99).

- Check validity of certificates for `www.lbvc4e6x3uemnx.com` and SANs.

---

Conclusion: This IP is associated with a hosting provider in Italy and exhibits Tor exit node activity. While not directly malicious, its subnet contains medium-risk neighbors, and the high-risk score warrants closer monitoring. SOC teams should prioritize isolating Tor-related traffic and validating TLS/SSH configurations.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฎ๐Ÿ‡น Italy
Region34
CityRovigo
TimezoneEurope/Rome
Latitude45.47
Longitude9.19

๐Ÿข Ownership & Registration

OrganizationLOWHOSTING-MNT
ASNAS212508
Network Nameโ€”
CIDR Block178.218.144.0/24
RIRRIPE
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR178.218.144.64.lowhosting.org
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnames178.218.144.64.lowhosting.org

๐Ÿ” DNS Hygiene

Hygiene Score60% (Good)
SPFPresent
DMARCPresent
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeMulti-Service Host
Network TierTier 3 โ€” Basic operator with some routing infrastructure
Hosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
22sshtcp
8443https-alttcpโ€”
Closed Ports25, 80, 443, 3389, 8080 (2 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”
SSH VersionSSH-2.0-OpenSSH_8.4p1 Debian-5+deb11u3

๐Ÿ” TLS Certificate

๐Ÿ”’
CN=www.oxatxocs.net
Issued by CN=www.m23xirz3rk6xekei.com
Self-signed: No
SANsNone
Valid From2026-05-11T00:00:00+00:00
Valid Until2026-08-22T00:00:00+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period103 days
Serial Number11AA02965F819E63
Thumbprint12DA430ADDAF1F1D5D2B293B5E21650F0BF13726

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
30%
24
routing
27%
23
services
21%
22
ownership
39%
37
reputation
26%
13
geolocation
32%
23
Overall29%1222
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-22 13:35:40 UTC
Last Seen2026-06-26 21:06:52 UTC
Profile Built2026-06-27 16:21:11 UTC
Data FreshnessLive
Signal Types29
Total Observations61
๐Ÿ” 29 signal types ยท 61 observations collected
This report is generated from 29+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.