IPDebrief

201.3.225.29

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 201.3.225.29

Classification: Moderate Risk (Score: 40/100)

Analysis Date: Current

Prepared For: SOC Analyst Team

---

## Executive Summary

IP 201.3.225.29 is a moderately risky endpoint operating under ASN 48031 (IPBNB LLC). The IP is classified as a Tor exit node and hosts web/SSH services. Network analysis reveals elevated abuse density within the 201.3.225.0/24 subnet, with three additional threat-sibling IPs identified. Recommended action: Block at perimeter.

---

## Network Classification & Ownership

AttributeValue
**Organization**IPBNB LLC (IPBNB Abuse Contact)
**ASN**48031
**CIDR Block**201.3.225.0/24
**Registration RIR**LACNIC
**Network Role**Tor Exit Nodes
**Country**PL (Poland)
**Geolocation**Stockholm, SE (inconsistent)

---

## Threat Indicators

---

## Service Exposure

PortProtocolService
443TCPHTTPS
22TCPSSH (OpenSSH_10.2p1 Ubuntu-2ubuntu3.5)

PTR Hostname: vm23379.bit.hosting

---

## Neighborhood Analysis (201.3.225.0/24)

Elevated-Risk Neighbors:

IPRisk ScoreAuthority Score
201.3.225.267050
201.3.225.206650
201.3.225.256650

---

## Observation History

---

## Relationship Graph

---

## Recommended Actions

Block the following IP at perimeter security devices:

```bash

# iptables

iptables -A INPUT -s 201.3.225.29 -j DROP

# nftables

nft add rule inet filter input ip saddr 201.3.225.29 drop

# nginx

deny 201.3.225.29;

# pfSense

201.3.225.29/32

# Cloudflare WAF

{"description":"Block 201.3.225.29 โ€” IPDebrief risk score 40","action":"block","filter":{"expression":"ip.src eq 201.3.225.29"}}

# AWS WAF

{"Addresses":["201.3.225.29/32"],"Description":"IPDebrief risk 40"}

```

---

## SOC Analyst Notes

1. Tor Exit Node Classification: This IP is flagged as a Tor exit node, which may be utilized for anonymity-based attacks or traffic exfiltration.

2. Subnet Correlation: The 201.3.225.0/24 subnet shows moderate abuse density. Monitor the three elevated-risk neighbors (201.3.225.26, 201.3.225.20, 201.3.225.25) for correlated activity.

3. Certificate Anomalies: TLS certificate uses cryptic domain names typical of malicious infrastructure. No legitimate service associated with these domains.

4. Geographic Inconsistency: IP registered in Poland but geolocation suggests Stockholm. Further investigation recommended if this discrepancy correlates with threat activity.

5. Historical Persistence: No evidence of persistent malicious behavior. IP shows mixed signals with some "Minimal" operator ratings.

Priority: Medium โ€” Block IP and monitor subnet neighbors for lateral threat activity.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ต๐Ÿ‡ฑ Poland
Regionโ€”
CityStockholm
TimezoneEurope/Warsaw
Latitude51.92
Longitude19.15

๐Ÿข Ownership & Registration

OrganizationIPBNB Abuse Contact
ASNAS48031
Network NameIPbnb-LLC
CIDR Block201.3.225.0/24
RIRLACNIC
CountryPL
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRvm23379.bit.hosting
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesvm23379.bit.hosting

๐Ÿ” DNS Hygiene

Hygiene Score60% (Good)
SPFPresent
DMARCPresent
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierTier 3 โ€” Basic operator with some routing infrastructure
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
443httpstcpโ€”
22sshtcp
Closed Ports25, 80, 3389, 8080, 8443 (2 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”
SSH VersionSSH-2.0-OpenSSH_10.2p1 Ubuntu-2ubuntu3.5

๐Ÿ” TLS Certificate

๐Ÿ”’
CN=www.qclc2inoe.net
Issued by CN=www.nru5oigekbc7eomvzu3.com
Self-signed: No
SANsNone
Valid From2026-05-10T00:00:00+00:00
Valid Until2026-09-09T00:00:00+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period122 days
Serial Number523D5145E5D80C6C
Thumbprint3793195F675376171D0855AAFE3DAA10F05367B6

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
59%
222
routing
34%
34
services
38%
23
ownership
32%
34
reputation
26%
13
geolocation
34%
23
Overall37%1339
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceMixed Signals (60%) โ€” 2 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Claimed geolocation contradicts RTT physics measurement
โš  Geo sources disagree on country: US, PL

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-07-25 20:19:16 UTC
Last Seen2026-08-13 10:40:13 UTC
Profile Built2026-08-13 10:07:57 UTC
Data FreshnessLive
Signal Types30
Total Observations77
๐Ÿ” 30 signal types ยท 77 observations collected
This report is generated from 30+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.