IP Intelligence Briefing: 192.121.44.33
*Generated via IPDebrief Analysis*
---
**Key Findings**
1. Risk Profile:
- Reputation: High Risk (Risk Score: 70).
- Threat Indicators: Identified as a Tor exit node (1 blacklist listing).
- Network Role: Classified as a Tor Exit Node with no active services or open ports.
2. Ownership & Geolocation:
- Organization: Playstar (AS199950).
- Geolocation: Registered to London, Sweden (SE).
- Subnet: 192.121.44.0/24 (abuse density: 0, classified as "clean").
3. Threat Observations:
- Observed as a Tor exit node with no persistent malicious activity.
- No known attacker campaigns or spam sources linked.
4. Network Relationships:
- Linked to tor-relay03.playstar.se (DNS PTR record).
- Subnet siblings (192.121.44.26β34) show mixed risk scores (0β70).
5. Control Plane & Routing:
- BGP prefix: 192.121.44.0/24.
- Route stability: Unstable (0 route changes in 30 days).
---
**Actionable Recommendations**
- Monitor Traffic: Track connections to/from this IP, as Tor exit nodes may anonymize malicious activity.
- Block if Necessary: Consider blocking traffic from this IP if it aligns with known malicious patterns or if itβs part of a larger network.
- Investigate Playstar: Review Playstarβs other IPs in the 192.121.44.0/24 subnet for potentialε ³θ.
- Check DNS: Monitor DNS requests to tor-relay03.playstar.se for unusual activity.
---
Note: This IP is flagged as a Tor exit node, which is a common vector for covert communication and data exfiltration. While no direct malicious activity was observed, its association with Tor infrastructure warrants further scrutiny.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Playstar |
| ASN | AS199950 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | tor-relay03.playstar.se |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | tor-relay03.playstar.se |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 21% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-22 13:35:42 UTC |
| Last Seen | 2026-06-26 21:06:49 UTC |
| Profile Built | 2026-06-27 17:20:04 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 51 |
Full dossier details are available via our API.