# IP Intelligence Briefing: 198.98.50.199
Classification: Moderate Risk / Tor Exit Node
Risk Score: 59/100
Date: 2026-06-20
---
## Executive Summary
IP 198.98.50.199 presents as a Tor exit node with moderate risk characteristics. The IP is registered to FranTech Solutions (ASN 53667) in Staten Island, NY. Key threat indicators include Tor exit node classification, a single blacklist listing, and one threat sibling in the local /24 subnet. The IP demonstrates persistent network-level routing with stable BGP prefix propagation.
---
## IP Profile & Ownership
- IP Address: 198.98.50.199/32
- Risk Score: 59/100 (Moderate Risk)
- Provider Score: 0
- Authority Score: 0
- Stability Score: 0
- Organization: FranTech Solutions
- ASN: 53667
- Registration RIR: ARIN
- Abuse Contact: Available via RDAP
---
## Geolocation Analysis
- Country: United States (US)
- Region: New York (NY)
- City: Staten Island
- Geographic Confidence: Plausible (GeoSource Count: 1, Consensus: True)
- Accuracy Radius: 2500 km
---
## Threat Indicators
| Indicator | Status |
|---|---|
| Tor Exit Node | **YES** |
| Known Attacker | No |
| Spam Source | No |
| Blacklist Count | 1 |
| Abuse Confidence Score | Not Available |
| Known Campaigns | None |
Threat Feed Observations: Tor exit indicators observed. The IP resolves to `tor-exit.cyberjake.xyz` via forward DNS resolution.
---
## Network Classification
- Role: Tor Exit Nodes
- Infrastructure Type: Not Classified
- Cloud Provider: No
- CDN: No
- VPN: No
- Proxy: No
- Hosting: No
- Mobile: No
- Residential: No
- Bogon: No
- Anycast: No
Service Status: Firewalled / No Services Detected
---
## DNS Analysis
- PTR Hostname: tor-exit.cyberjake.xyz
- Forward Resolution: tor-exit.cyberjake.xyz (Count: 1)
- Forward Confirmed: No
- Hosted Domain Count: 0
- Email Authentication: SPF: Yes, DMARC: Yes
- TXT Record Count: 0
---
## Control Plane & Routing
- Origin ASN: 53667
- BGP Prefix: 198.98.48.0/20
- AS Path: 6939 β 53667
- RPKI State: Not Available
- IRR Consistency: Not Available
- Route Changes (30d): 0
- Route Stability: Stable
- DNSSEC Valid: Yes
- DNSBL Listed: 1/8 total lists
Delegation Age: 5,667 days (~15.5 years)
---
## Observation History
Total Signals Observed: 57
Recent Activity (2026-06-20):
- 06:49:17 UTC β Basic classification signal (Operator Score: 0.2609)
- 12:50:41 UTC β Basic classification signal (Operator Score: 0.2609)
The IP maintains consistent classification signals across multiple observation windows with stable routing characteristics. No significant threat escalation detected in historical data.
---
## Neighborhood Analysis (/24 Subnet)
- Subnet: 198.98.50.0/24
- Abuse Density: 0.5
- Classification: Mostly Clean
- Total Siblings: 2
- Active Siblings: 2
- Threat Siblings: 1
- Inherited Risk: 2
Neighbor Risk Distribution:
| Risk Level | Count |
|---|---|
| High | 0 |
| Medium | 1 |
| Low | 0 |
Notable Neighbor: 198.98.50.7 (Risk Score: 40, Authority Score: 60)
---
## Related Entities
Network Relationships: 332 total relationships identified
- Primary association: PONYNET-06 (Multiple entries)
- No direct hostname, organization, or certificate relationships beyond network-level associations
---
## Recommended Security Actions
Access Control
| Category | Action | Severity |
|---|---|---|
| Access Control | Consider enhanced verification for anonymous traffic | Medium |
| Monitoring | Increase logging verbosity and review recent activity from this IP | High |
Firewall Rules
iptables:
```bash
iptables -A INPUT -s 198.98.50.199 -j DROP
```
nftables:
```bash
nft add rule inet filter input ip saddr 198.98.50.199 drop
```
nginx:
```nginx
deny 198.98.50.199;
```
pfSense:
```
198.98.50.199/32
```
Cloudflare WAF:
```json
{"description":"Block 198.98.50.199 β IPDebrief risk score 59","action":"block","filter":{"expression":"ip.src eq 198.98.50.199"}}
```
AWS WAF:
```json
{"Addresses":["198.98.50.199/32"],"Description":"IPDebrief risk 59"}
```
---
## Assessment Summary
IP 198.98.50.199 operates as a Tor exit node with moderate risk profile. The single blacklist listing, Tor exit classification, and one threat sibling in the local subnet warrant defensive measures. Recommended actions include enhanced logging for traffic analysis and consideration of blocking at perimeter controls. The IP demonstrates stable routing and no recent escalation in threat activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | FranTech Solutions |
| ASN | AS53667 |
| Network Name | β |
| CIDR Block | 198.98.48.0/20 |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | tor-exit.cyberjake.xyz |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | tor-exit.cyberjake.xyz |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 17% | 2 | 3 |
| services | 12% | 2 | 2 |
| ownership | 29% | 3 | 6 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 25% | 12 | 21 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-22 13:35:43 UTC |
| Last Seen | 2026-06-28 19:25:29 UTC |
| Profile Built | 2026-06-29 07:28:46 UTC |
| Data Freshness | Live |
| Signal Types | 28 |
| Total Observations | 55 |
Full dossier details are available via our API.