IPDebrief

195.154.170.135

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

IP Intelligence Briefing: 195.154.170.135

*Last Updated: 2026-06-08*

---

**1. Core Profile**

- Tor exit node (confirmed).

- DNS associations with `notorture.deuza.bzh` (mixed reputation).

- Moderate operator risk score (0.52).

---

**2. Threat Observations**

- PTR hostname: `notorture.deuza.bzh` (linked to mixed reputation).

- DNSSEC and CAA records present but not fully validated.

- Open ports: 80 (HTTP), 443 (HTTPS).

- TLS certificate issued by Let’s Encrypt, valid for `notorture.deuza.bzh`.

- Server banner: Apache.

---

**3. Temporal Trends**

- Recent signals (June 7–8, 2026) show consistent moderate risk.

- No significant changes in threat indicators or network behavior.

- BGP route stability: Stable (no recent route changes).

- Geolocation consistency: Paris, France (500m radius).

---

**4. Network Relationships**

- DNS: `notorture.deuza.bzh` (mixed reputation).

- Network: Scaleway (AS12876).

- Subnet: 195.154.170.0/24 (no neighboring IPs reported).

- No direct links to known malicious campaigns or blacklists.

---

**5. Recommendations**

- Track traffic originating from this Tor exit node, as it may be used for covert communication or data exfiltration.

- Monitor DNS queries to `notorture.deuza.bzh` for suspicious activity.

- Consider blocking Tor exit nodes in your network unless explicitly required.

- Apply rules to restrict HTTP/HTTPS traffic from this IP unless authorized.

- Validate the legitimacy of `notorture.deuza.bzh` and its associated services.

---

Next Steps:

*Generated by IPDebrief intelligence analysis.*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡«πŸ‡· France
RegionÎle-de-France
CityParis
TimezoneEurope/Paris
Latitude48.86
Longitude2.35

🏒 Ownership & Registration

OrganizationSCALEWAY
ASNAS12876
Network Nameβ€”
CIDR Block195.154.0.0/16
RIRRIPE
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRnotorture.deuza.bzh
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamesnotorture.deuza.bzh

πŸ” DNS Hygiene

Hygiene Score100% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAAPresent

☁️ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierTier 3 β€” Basic operator with some routing infrastructure
Tor

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpβ€”
443httpstcpβ€”
Closed Ports22, 25, 3389, 8080, 8443 (2 open / 7 scanned)
ServerApache
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
CN=notorture.deuza.bzh
Issued by CN=E8, O=Let's Encrypt, C=US
Self-signed: No
SANsnotorture.deuza.bzh
Valid From2026-05-23T06:42:38+00:00
Valid Until2026-08-21T06:42:37+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha384ECDSA
Validity Period89 days
Serial Number05608BDC4B4E041044085E9B982F21B5FF07
ThumbprintC06F976701236C0BC261D44B8E30A55B0CED924D

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
31%
24
routing
20%
23
services
27%
23
ownership
32%
39
reputation
29%
13
geolocation
34%
23
Overall29%1225
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceMostly Consistent (85%) β€” 1 contradiction(s)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ High authority score (70) but appears on threat lists (risk 49)

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-23 06:35:38 UTC
Last Seen2026-06-28 20:45:48 UTC
Profile Built2026-06-29 02:48:48 UTC
Data FreshnessLive
Signal Types32
Total Observations49
πŸ” 32 signal types Β· 49 observations collected
This report is generated from 32+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.