# INTELLIGENCE BRIEFING: 185.225.226.42
Classification: MODERATE RISK / TOR EXIT NODE INFRASTRUCTURE
Date: 2026-07-22
Analyst: IPDebrief Intelligence Service
---
## EXECUTIVE SUMMARY
IP 185.225.226.42 is identified as a Tor exit node with moderate risk scoring (59/100). The address is registered to individual owner Zubritska Valeriia Nikolaevna under netname UA-ZUBRITSKA-20200106, operating from Kyiv, Ukraine via ASN 207560. The IP presents web server services (HTTP/HTTPS) and SSH access, with observed Tor exit node indicators requiring access control review.
---
## RISK ASSESSMENT
| Metric | Value |
|---|---|
| **Risk Score** | 59/100 (Moderate Risk) |
| **Provider Score** | 0 |
| **Authority Score** | 0 |
| **Abuse Confidence** | Not quantified |
| **Blacklist Status** | 1 DNSBL entry, 1 threat feed match |
Primary Risk Factor: Tor exit node indicators observed with 1 blacklist listing.
---
## OWNERSHIP & NETWORK ATTRIBUTION
- Organization: Zubritska Valeriia Nikolaevna (Individual)
- ASN: 207560
- Netname: UA-ZUBRITSKA-20200106
- RIR: RIPE (delegation age: 2,374 days)
- CIDR Block: 185.225.226.0/24
- Geolocation: Kyiv, Ukraine (UA)
- BGP Origin: 185.225.226.0/24 via path 293 → 3326 → 35680 → 207560
---
## THREAT INTELLIGENCE
Active Indicators
- Tor Exit Node: Confirmed (isTorExit: true)
- Known Campaigns: None identified
- Attacker Classification: Not flagged as known attacker
- Spam Source: Not flagged
- Scan Activity: 53 historical observations recorded
Network Role Classification
- Primary Role: Tor Exit Nodes
- Infrastructure Type: Unknown
- Cloud/CDN/VPN/Proxy: Negative across all categories
- Connection Type: Web Server
---
## SERVICE & PORT EXPOSURE
| Port | Protocol | Service | Status |
|---|---|---|---|
| 80 | TCP | HTTP | Open |
| 443 | TCP | HTTPS | Open |
| 22 | TCP | SSH | Open |
TLS Certificate Analysis:
- Issuer: CN=www.47zhjfl6fl4fh.com
- Subject: CN=www.ctlcpfklxxxu.net
- Certificate Type: Self-signed
- Protocol: TLS 1.3 (TLS_AES_256_GCM_SHA384)
- Note: Self-signed certificate indicates potential security weakness
SSH Configuration:
- Version: SSH-2.0-OpenSSH_10.0p2 Debian-7+deb13u4
- Server Banner: Detected
---
## DNS & DOMAIN RESOLUTION
- PTR Record: 42.226.225.185.vikhost.com
- Forward Confirmation: Not confirmed (forward lookup failed)
- Hosted Domain: vikhost.com
- Email Authentication: SPF and DMARC records present
- Reverse DNS: Single forward hostname resolution
---
## NEIGHBORHOOD ANALYSIS (185.225.226.0/24)
- Subnet Classification: mostly_clean
- Abuse Density: 0 (low)
- Total Siblings: 2 active IPs in /24
- Risk Distribution: 0 high, 0 medium, 2 low risk
- Neighbor IPs:
- 185.225.226.62 (Risk: 0, Authority: 50)
- 185.225.226.63 (Risk: 0, Authority: 50)
Assessment: The /24 subnet shows minimal abuse correlation with the target IP.
---
## TEMPORAL ANALYSIS
- Observation Count: 53 historical signals
- Recent Activity: Multiple observations on 2026-07-22 (01:59, 05:24, 08:13, 14:21 UTC)
- Ownership Changes: 0 (stable ownership)
- Threat Persistence: Not persistently malicious (0 threat persistence days)
- Route Stability: Unstable (1 route change in 30 days)
---
## RELATIONSHIP GRAPH
- Total Relationships: 118 linked entities
- Primary Links: Same Network (UA-ZUBRITSKA-20200106) - 113+ duplicates indicating network-level association
- Entity Types: Networks, subnets, organizational affiliations
---
## RECOMMENDED ACTIONS
Access Control (High Severity)
```
iptables: iptables -A INPUT -s 185.225.226.42 -j DROP
nftables: nft add rule inet filter input ip saddr 185.225.226.42 drop
nginx: deny 185.225.226.42;
```
Enhanced Monitoring (High Severity)
```
pfsense: 185.225.226.42/32 (add to monitoring list)
Cloudflare WAF: Block 185.225.226.42 — IPDebrief risk score 59
AWS WAF: Addresses: ["185.225.226.42/32"]
```
Rationale: Tor exit nodes are commonly exploited for traffic anonymization, potential
Rationale
Tor exit nodes are commonly exploited for traffic anonymization, potential credential harvesting, and spam relaying. The elevated risk score correlates with Tor exit node indicators and observed blacklist listings. The subnet maintains low abuse density, suggesting isolated threat behavior rather than coordinated campaign activity.
---
## TECHNICAL SIGNATURES
Fingerprint Data:
- Server Fingerprint: Not identified
- Status Code: Not identified
- HSTS Configuration: Data available but not expanded
Control Plane:
- Origin ASN: 207560
- RPKI State: Not validated in current dataset
- IRR Consistency: Not validated in current dataset
- DNSSEC: Valid
- CAA Records: Present
---
## GEOVALIDATION
- Geolocation Plausibility: True
- Distance from Probe: 1,663.7 km
- Minimum RTT: 139 ms
- Average RTT: 144 ms
- Probe Count: 5
- Violation Status: None detected
---
## CAMPAIGN CORRELATION
- Campaign Likelihood: None
- CERT Matches: 0
- Banner Matches: 0
- Correlated IPs: 0
- Certificate Subjects: None identified
---
## RECOMMENDATIONS
| Category | Action | Severity |
|---|---|---|
| Access Control | Consider enhanced verification for anonymous traffic | Medium |
| Monitoring | Increase logging verbosity and review recent activity from this IP | High |
---
## CONCLUSION
IP 185.225.226.42 warrants defensive monitoring due to confirmed Tor exit node operation and moderate risk scoring. The IP maintains stable ownership within a low-abuse-density subnet. Recommend implementing the provided firewall rules and enhanced logging procedures for SOC teams. No evidence of persistent malicious activity or known campaign association observed in current datasets.
---
Report Generated: 2026-07-22
Data Source: IPDebrief Threat Intelligence Platform
Classification: Defensive Security Intelligence
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Zubritska Valeriia Nikolaevna |
| ASN | AS207560 |
| Network Name | UA-ZUBRITSKA-20200106 |
| CIDR Block | 185.225.226.0/24 |
| RIR | RIPE |
| Country | UA |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | 42.226.225.185.vikhost.com |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 42.226.225.185.vikhost.com |
🔐 DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Tier 3 — Basic operator with some routing infrastructure |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 443 | https | tcp | — |
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | 2026-04-12T00:00:00+00:00 |
| Valid Until | 2026-09-30T00:00:00+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 171 days |
🛡️ Public Network Snapshot
| Origin ASN | AS207560 |
| Network Prefix | 185.225.226.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 27% | 2 | 3 |
| services | 37% | 2 | 3 |
| ownership | 35% | 3 | 5 |
| reputation | 30% | 1 | 3 |
| geolocation | 31% | 2 | 3 |
| Overall | 32% | 12 | 21 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-04 22:50:11 UTC |
| Last Seen | 2026-08-27 04:11:09 UTC |
| Profile Built | 2026-09-03 04:11:48 UTC |
| Data Freshness | Live |
| Signal Types | 27 |
| Total Observations | 29 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 185.225.226.42
Who owns the IP address 185.225.226.42?
185.225.226.42 is registered to Zubritska Valeriia Nikolaevna. The address falls within the 185.225.226.0/24 network block. Registration is held at RIPE.
Where is 185.225.226.42 located?
Geolocation data places 185.225.226.42 in Kyiv, Kyiv City, Ukraine. The local time zone is Europe/Kyiv. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 185.225.226.42 malicious or safe?
185.225.226.42 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 185.225.226.42?
The reverse DNS (PTR) record for 185.225.226.42 is 42.226.225.185.vikhost.com. This hostname is not forward-confirmed, so it should be treated as a weak signal.
What ports are open on 185.225.226.42?
Responsive ports observed on 185.225.226.42 include 80, 443, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.
Is 185.225.226.42 a VPN, proxy, or data center address?
185.225.226.42 is classified as the Tor network based on network ownership and behavioural analysis.