# IP Intelligence Briefing: 201.3.225.29
Classification: Moderate Risk (Score: 40/100)
Analysis Date: Current
Prepared For: SOC Analyst Team
---
## Executive Summary
IP 201.3.225.29 is a moderately risky endpoint operating under ASN 48031 (IPBNB LLC). The IP is classified as a Tor exit node and hosts web/SSH services. Network analysis reveals elevated abuse density within the 201.3.225.0/24 subnet, with three additional threat-sibling IPs identified. Recommended action: Block at perimeter.
---
## Network Classification & Ownership
| Attribute | Value |
|---|---|
| **Organization** | IPBNB LLC (IPBNB Abuse Contact) |
| **ASN** | 48031 |
| **CIDR Block** | 201.3.225.0/24 |
| **Registration RIR** | LACNIC |
| **Network Role** | Tor Exit Nodes |
| **Country** | PL (Poland) |
| **Geolocation** | Stockholm, SE (inconsistent) |
---
## Threat Indicators
- Risk Score: 40/100 (Moderate)
- Control Plane: Operator score 0.1304 (Minimal)
- DNSBL Listed: 2/8 lists
- Tor Exit Node: Yes
- Known Attacker: No
- Spam Source: No
- TLS Certificate: Self-signed; issuer CN=www.jcbl5tfmz5wrvvyvger4.com; subject CN=www.t25lqspzhx.net
---
## Service Exposure
| Port | Protocol | Service |
|---|---|---|
| 443 | TCP | HTTPS |
| 22 | TCP | SSH (OpenSSH_10.2p1 Ubuntu-2ubuntu3.5) |
PTR Hostname: vm23379.bit.hosting
---
## Neighborhood Analysis (201.3.225.0/24)
- Subnet Abuse Density: 0.3 (Moderate)
- Total Siblings: 10
- Threat Siblings: 3
- Risk Distribution: 0 High, 4 Medium, 5 Low
Elevated-Risk Neighbors:
| IP | Risk Score | Authority Score |
|---|---|---|
| 201.3.225.26 | 70 | 50 |
| 201.3.225.20 | 66 | 50 |
| 201.3.225.25 | 66 | 50 |
---
## Observation History
- Total Observations: 23 signals over recent period
- Recent Signals: Multiple operator signals labeled "Minimal" (score 0.15)
- Persistence: No persistent malicious behavior observed
- Threat Persistence Days: 0
---
## Relationship Graph
- Network Association: IPBNB-LLC (multiple same-network relationships)
- DNS Association: vm23379.bit.hosting (primary hostname)
---
## Recommended Actions
Block the following IP at perimeter security devices:
```bash
# iptables
iptables -A INPUT -s 201.3.225.29 -j DROP
# nftables
nft add rule inet filter input ip saddr 201.3.225.29 drop
# nginx
deny 201.3.225.29;
# pfSense
201.3.225.29/32
# Cloudflare WAF
{"description":"Block 201.3.225.29 โ IPDebrief risk score 40","action":"block","filter":{"expression":"ip.src eq 201.3.225.29"}}
# AWS WAF
{"Addresses":["201.3.225.29/32"],"Description":"IPDebrief risk 40"}
```
---
## SOC Analyst Notes
1. Tor Exit Node Classification: This IP is flagged as a Tor exit node, which may be utilized for anonymity-based attacks or traffic exfiltration.
2. Subnet Correlation: The 201.3.225.0/24 subnet shows moderate abuse density. Monitor the three elevated-risk neighbors (201.3.225.26, 201.3.225.20, 201.3.225.25) for correlated activity.
3. Certificate Anomalies: TLS certificate uses cryptic domain names typical of malicious infrastructure. No legitimate service associated with these domains.
4. Geographic Inconsistency: IP registered in Poland but geolocation suggests Stockholm. Further investigation recommended if this discrepancy correlates with threat activity.
5. Historical Persistence: No evidence of persistent malicious behavior. IP shows mixed signals with some "Minimal" operator ratings.
Priority: Medium โ Block IP and monitor subnet neighbors for lateral threat activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IPBNB Abuse Contact |
| ASN | AS48031 |
| Network Name | IPbnb-LLC |
| CIDR Block | 201.3.225.0/24 |
| RIR | LACNIC |
| Country | PL |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vm23379.bit.hosting |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | vm23379.bit.hosting |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_10.2p1 Ubuntu-2ubuntu3.5 |
๐ TLS Certificate
| SANs | None |
| Valid From | 2026-05-10T00:00:00+00:00 |
| Valid Until | 2026-09-09T00:00:00+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 122 days |
| Serial Number | 523D5145E5D80C6C |
| Thumbprint | 3793195F675376171D0855AAFE3DAA10F05367B6 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 59% | 2 | 22 |
| routing | 34% | 3 | 4 |
| services | 38% | 2 | 3 |
| ownership | 32% | 3 | 4 |
| reputation | 26% | 1 | 3 |
| geolocation | 34% | 2 | 3 |
| Overall | 37% | 13 | 39 |
| Data Coherence | Mixed Signals (60%) โ 2 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
โ Geo sources disagree on country: US, PL
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-25 20:19:16 UTC |
| Last Seen | 2026-08-13 10:40:13 UTC |
| Profile Built | 2026-08-13 10:07:57 UTC |
| Data Freshness | Live |
| Signal Types | 30 |
| Total Observations | 77 |
Full dossier details are available via our API.