# IP Intelligence Briefing: 188.116.36.143/32
## Executive Summary
IP address 188.116.36.143 presents a Low Risk profile with an overall risk score of 25. While classified as a Tor exit node provider, the IP demonstrates minimal malicious activity indicators and is listed on multiple DNS blacklists. No immediate threat indicators were observed across the full intelligence dataset.
---
## Ownership & Network Classification
- ASN: 60117
- Organization: Ali Al-Attiyah
- Netname: AE-SAILORHOST-20090529
- CIDR Block: 188.116.36.0/24
- Network Classification: Provider (Tor Exit Nodes)
- Registration RIR: RIPE
---
## Geolocation Analysis
- Primary Location: Romania (RO), coordinates 45.94°N, 24.97°E
- Timezone: Europe/Bucharest
- Geolocation Confidence: Consensus confirmed across multiple sources (geoPlausible: true)
- RTT Metrics: Minimum 3.4ms, Average 100.2ms across 5 probes
Anomaly Note: Recent network observation traced via Cogentco transit infrastructure through London, UK (LHR) during 2026-07-30T20:29:13 UTC, suggesting routing variation or potential geo-spoofing.
---
## Threat Indicators
| Indicator | Status |
|---|---|
| Known Attacker | No |
| Spam Source | No |
| Tor Exit Node | Yes |
| DNSBL Listed | Yes (8 lists, 1 current listing) |
| Campaign Likelihood | None |
| Threat Persistence | 0 days |
| Abuse Confidence Score | Not available |
---
## Service Footprint
- HTTP (80/tcp): Open, Apache/2.4.58 (Ubuntu)
- HTTPS (443/tcp): Open
- SSH (22/tcp): Open, OpenSSH_9.6p1 Ubuntu-3ubuntu13.18
TLS Certificate Analysis:
- Issuer: CN=www.lwnjujb7nmowbl.com
- Subject: CN=www.k75ext2edpq.net
- Assessment: Self-signed certificate with non-standard domain naming pattern
---
## Network Neighborhood Assessment
- Subnet: 188.116.36.0/24
- Abuse Density: 0 (Clean)
- Total Siblings: 2
- Active Siblings: 1
- Threat Siblings: 0
- Neighbor Risk Profile: Single neighbor (188.116.36.169) with matching risk score of 25
---
## Temporal Analysis
- Observation Count: 23 total signals over monitoring period
- Ownership Stability: 0 changes recorded
- Threat Observation Count: 0
- Persistent Malicious Activity: False
- Route Stability: False (route changes observed within 30-day window)
---
## Recommended Actions
- Firewall/IPS Rules: No specific blocking rules recommended at current risk level
- Monitoring: Continue passive monitoring; maintain alerting on port 22 (SSH) and 443 (HTTPS) traffic
- Geolocation Verification: Investigate routing discrepancy between Romania (profile) and UK (observation) paths
---
## Intelligence Assessment
The IP address operates within a low-risk subnet with minimal abuse indicators. The Tor exit node classification combined with DNS blacklist listings suggests potential for abuse, though current risk scoring indicates limited active threat. The suspicious TLS certificate domain patterns warrant continued monitoring. No immediate threat mitigation required; standard network hygiene practices apply.
Classification: LOW RISK โ Monitor
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ali Al-Attiyah |
| ASN | AS60117 |
| Network Name | AE-SAILORHOST-20090529 |
| CIDR Block | 188.116.36.0/24 |
| RIR | RIPE |
| Country | RO |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 143.128-191.36.116.188.in-addr.arpa |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 143.128-191.36.116.188.in-addr.arpa |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | Apache/2.4.58 (Ubuntu) |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18 |
๐ TLS Certificate
| SANs | None |
| Valid From | 2026-06-22T00:00:00+00:00 |
| Valid Until | 2026-09-17T00:00:00+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 87 days |
| Serial Number | 046188AE5FFF4540 |
| Thumbprint | 3982DB02185B6FBC9FC5B22C96B1096F89F768FF |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 60% | 2 | 22 |
| routing | 32% | 2 | 3 |
| services | 37% | 2 | 3 |
| ownership | 32% | 3 | 4 |
| reputation | 26% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 36% | 12 | 38 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-27 21:33:09 UTC |
| Last Seen | 2026-08-13 12:41:33 UTC |
| Profile Built | 2026-08-13 12:06:31 UTC |
| Data Freshness | Live |
| Signal Types | 30 |
| Total Observations | 74 |
Full dossier details are available via our API.