IPDebrief

201.3.225.25

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 201.3.225.25/32

Classification: HIGH RISK โ€“ Tor Exit Node Infrastructure

Date: Analysis completed based on latest available data

Risk Score: 70/100

## Executive Summary

IP 201.3.225.25 is classified as a Tor exit node provider operating under ASN 48031 (IPBNB Abuse Contact, netname: IPbnb-LLC). The IP shows Tor exit node indicators and is listed on 1 DNSBL. This classification indicates the IP is used as an endpoint for anonymized Tor traffic, which may facilitate malicious activity or legitimate privacy concerns.

## Technical Profile

Network Attribution:

Service Exposure:

## Threat Indicators

Positive Identifiers:

Negative Identifiers:

## Temporal Analysis

Recent observation history (July 29, 2026) shows:

## Neighborhood Context

Subnet 201.3.225.0/24 analysis:

## Recommended Actions

Access Control:

```bash

# Block at perimeter firewall

iptables -A INPUT -s 201.3.225.25 -j DROP

nft add rule inet filter input ip saddr 201.3.225.25 drop

```

Web Server Protection:

```nginx

# If using nginx

deny 201.3.225.25;

```

Cloud WAF Rules:

Monitoring:

## Analyst Notes

The IP's classification as a Tor exit node does not automatically indicate malicious intent, but requires heightened scrutiny. The IP's service classification as "Web Server" combined with SSH access suggests potential for abuse. Consider allowing traffic only if legitimate business justification exists, and implement enhanced monitoring. The subnet's low abuse density (0%) suggests this may be an isolated elevated-risk IP rather than part of a broader malicious campaign.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ต๐Ÿ‡ฑ Poland
Regionโ€”
CityStockholm
TimezoneEurope/Warsaw
Latitude51.92
Longitude19.15

๐Ÿข Ownership & Registration

OrganizationIPBNB Abuse Contact
ASNAS48031
Network NameIPbnb-LLC
CIDR Block201.3.225.0/24
RIRLACNIC
CountryPL
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRvm23367.bit.hosting
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesvm23367.bit.hosting

๐Ÿ” DNS Hygiene

Hygiene Score60% (Good)
SPFPresent
DMARCPresent
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierTier 3 โ€” Basic operator with some routing infrastructure
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
443httpstcpโ€”
22sshtcp
Closed Ports25, 80, 3389, 8080, 8443 (2 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”
SSH VersionSSH-2.0-OpenSSH_10.2p1 Ubuntu-2ubuntu3.5

๐Ÿ” TLS Certificate

๐Ÿ”’
CN=www.cm23v2dfvfm6t4ix.net
Issued by CN=www.a5cmayab7a25uki4tr.com
Self-signed: No
SANsNone
Valid From2026-08-08T00:00:00+00:00
Valid Until2026-08-16T23:59:59+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period8 days
Serial Number785E8268CE13CF09
ThumbprintC8CDDC0B3FD8C99B32CEB40D05C3CB7D15CF3486

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
60%
218
routing
34%
34
services
37%
23
ownership
32%
34
reputation
26%
13
geolocation
31%
23
Overall37%1335
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceMixed Signals (60%) โ€” 2 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Claimed geolocation contradicts RTT physics measurement
โš  Geo sources disagree on country: US, PL

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-07-25 19:18:27 UTC
Last Seen2026-08-13 11:40:53 UTC
Profile Built2026-08-13 10:27:05 UTC
Data FreshnessLive
Signal Types30
Total Observations72
๐Ÿ” 30 signal types ยท 72 observations collected
This report is generated from 30+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.