## Threat Intelligence Briefing: 203.12.31.167/32
Date: 2026-08-10
Classification: Moderate Risk
Prepared by: IPDebrief Intelligence Analysis
---
Executive Summary
IP address 203.12.31.167 is a Tor exit node associated with ASN 210083 (SE-OMA-19950123) originating from the APNIC region. The address presents a moderate risk profile (score: 59) with confirmed Tor exit node activity and one DNSBL listing. No active services or open ports were detected on the IP. The subnet environment shows low-to-moderate abuse density (0.25), with three neighboring IPs exhibiting comparable risk scores (49-59).
---
Technical Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 59 (Moderate) |
| **ASN** | 210083 |
| **Organization** | lir-se-oma-1-MNT |
| **CIDR** | 203.12.31.0/24 |
| **Geolocation** | Stockholm, SE (APNIC RIR) |
| **Timezone** | Europe/Stockholm |
| **Network Role** | Tor Exit Node |
| **Threat Indicators** | Tor exit node indicators observed |
| **Blacklist Status** | Listed on 1 of 8 DNSBLs |
| **Route Stability** | Stable (no changes in 30 days) |
---
Threat Assessment
Primary Risk Factor: Tor Exit Node Activity
- The IP is classified as a Tor exit node, which is a known infrastructure component for anonymized traffic
- Tor exit nodes are commonly used by legitimate privacy users but also exploited by threat actors to mask malicious origin
- One blacklisting event recorded, with DNSBL presence across 8 total threat feeds
Observed Signals:
- No active services detected (no open ports, no TLS certificates, no HTTP banners)
- Service classification: "Firewalled / No Services"
- No email authentication records (no SPF/DMARC)
- No reverse DNS entries
Temporal Analysis:
- Single threat observation recorded
- Not persistently malicious (threatPersistenceDays: 0)
- Ownership stability: No ownership changes observed
- History shows 40 total observations across routing, threat, and service signal types
---
Neighborhood Analysis
Subnet: 203.12.31.0/24
- Abuse Density: 0.25 (low-moderate)
- Total Siblings: 4
- Active Siblings: 4
- Threat Siblings: 1
Notable Neighbors:
| IP Address | Risk Score | Authority Score |
|---|---|---|
| 203.12.31.87 | 49 | 50 |
| 203.12.31.99 | 49 | 50 |
| 203.12.31.101 | 59 | 50 |
The subnet contains three additional active IP addresses, all with moderate risk scores (49-59). One neighbor (203.12.31.101) matches the risk profile of the target IP.
---
Relationships
The IP maintains 395 relationships primarily linked to the network identifier SE-OMA-19950123. All relationships are classified as "Same Network," indicating the IP is part of a larger infrastructure cluster with consistent routing and ownership attributes.
---
Recommended Actions
SOC/Security Operations:
1. Monitor for Tor Traffic Patterns: Flag any outbound connections to this IP as potentially anonymized traffic requiring investigation
2. Block at Perimeter: Consider blocking inbound connections to this IP at network perimeter if not required for business operations
3. Correlate with Logs: Search SIEM for connection attempts from known Tor exit node IP ranges
4. Whitelist Decision: Evaluate if this IP should be whitelisted for legitimate use cases (e.g., privacy-focused users, CDN providers)
Firewall Rules (iptables/nftables):
```
# Recommended: Block Tor exit nodes (adjust as needed for business requirements)
iptables -A INPUT -s 203.12.31.167/32 -j DROP
```
Cloudflare/AWS WAF:
- Consider adding to blocklist with risk-based rule: `risk_score > 50 AND is_tor_exit_node = true`
---
Intelligence Notes
- The IP exhibits stable routing characteristics with no route changes in the past 30 days
- BGP path: 6939 → 400587 → 210083
- RPKI validation status: Not applicable (state null)
- Geolocation validation: ICMP blocked, unable to validate via probe
- No associated campaigns or known attack infrastructure linked to this IP
---
Status: Monitor. This IP represents a known Tor exit node with moderate risk. No immediate threat indicators, but traffic from Tor exit nodes should be treated as potentially suspicious depending on organizational policy.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | lir-se-oma-1-MNT |
| ASN | AS210083 |
| Network Name | SE-OMA-19950123 |
| CIDR Block | 203.12.31.0/24 |
| RIR | APNIC |
| Country | SE |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 — Basic operator with some routing infrastructure |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS210083 |
| Network Prefix | 203.12.31.0/24 |
| Route mapping | Found |
| RPKI Status | Valid |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 26% | 2 | 3 |
| services | 12% | 2 | 2 |
| ownership | 37% | 3 | 5 |
| reputation | 27% | 1 | 3 |
| geolocation | 23% | 2 | 3 |
| Overall | 25% | 12 | 20 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (65%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-06 11:47:31 UTC |
| Last Seen | 2026-08-27 02:21:45 UTC |
| Profile Built | 2026-08-29 06:29:15 UTC |
| Data Freshness | Live |
| Signal Types | 27 |
| Total Observations | 29 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 203.12.31.167
Who owns the IP address 203.12.31.167?
203.12.31.167 is registered to lir-se-oma-1-MNT. The address falls within the 203.12.31.0/24 network block. Registration is held at APNIC.
Where is 203.12.31.167 located?
Geolocation data places 203.12.31.167 in Amsterdam, North Holland, Sweden. The local time zone is Europe/Stockholm. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 203.12.31.167 malicious or safe?
203.12.31.167 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
Is 203.12.31.167 a VPN, proxy, or data center address?
203.12.31.167 is classified as the Tor network based on network ownership and behavioural analysis.