IPDebrief

212.86.116.26

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 212.86.116.26

## Executive Summary

The IP address 212.86.116.26 presents a Moderate Risk profile (Score: 59/100) with confirmed Tor exit node indicators. The address is associated with a Ukrainian infrastructure network (ASN 6698, UA-VSYS) and is classified as a Tor exit node provider, presenting potential anonymity-related risks for inbound traffic.

## Technical Profile

Network Attribution

Service Exposure

Threat Indicators

## Historical Activity

The IP has generated 36 total observations in the monitoring database. Recent signal activity includes:

## Neighborhood Analysis

The /24 subnet (212.86.116.0/24) shows:

## Risk Assessment

The primary risk factor is the confirmed Tor exit node classification. Tor exit nodes are commonly used to anonymize malicious traffic, though they can also serve legitimate purposes. The moderate risk score (59/100) reflects this mixed-use profile. Route instability suggests potential infrastructure changes or temporary hosting arrangements.

## Recommended Actions

Immediate Mitigation

1. Access Control: Implement enhanced verification for traffic from this IP, particularly for authentication-sensitive services

2. Logging: Increase verbosity and retention for all traffic from 212.86.116.26

Firewall Rules

```

iptables: iptables -A INPUT -s 212.86.116.26 -j DROP

nftables: nft add rule inet filter input ip saddr 212.86.116.26 drop

nginx: deny 212.86.116.26;

Cloudflare WAF: Block IP (risk score 59/100)

AWS WAF: Add to blocklist (212.86.116.26/32)

```

SOC Monitoring Priorities

## Conclusion

This IP should be blocked or subjected to enhanced scrutiny depending on organizational risk tolerance. The Tor exit node designation warrants defensive blocking for systems requiring strict trust boundaries. Monitor the subnet 212.86.116.0/24 for correlated activity from the identified threat sibling.

---

*Intel generated from IPDebrief analysis. Review firewall rules in conjunction with organizational security policies.*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇺🇦 Ukraine
RegionKyiv City
CityKyiv
TimezoneEurope/Kyiv
Latitude50.46
Longitude30.53

🏢 Ownership & Registration

OrganizationVyacheslav Smyrnov
ASNAS6698
Network NameUA-VSYS
CIDR Block212.86.116.0/24
RIRRIPE
CountryUA
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRdedicated.vsys.host
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesdedicated.vsys.host

🔐 DNS Hygiene

Hygiene Score60% (Good)
SPFPresent
DMARCPresent
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierUnknown — Insufficient routing data to classify
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
80httptcp—
443httpstcp—
22sshtcpBanner detected
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
Server—
HTTP Title—

🔐 TLS Certificate

An expired certificate for CN=www.aiyeojlfnsnke7.net was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.
🔒
CN=www.aiyeojlfnsnke7.net
Issued by CN=www.qfzhs3o3ioranlnzq.com
Self-signed: No
SANsNone
Valid From2026-01-29T00:00:00+00:00
Valid Until2026-09-24T23:59:59+00:00 (expired)
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period238 days

🛡️ Public Network Snapshot

Origin ASNAS6698
Network Prefix212.86.116.0/24
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
59%
221
routing
27%
23
services
35%
23
ownership
39%
37
reputation
26%
13
geolocation
32%
23
Overall36%1240
Coverage: 6/6 dimensions · Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) — 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Geo sources disagree on country: GI, UA

📅 Observation Timeline 🔄 Live

First Seen2026-07-04 22:50:11 UTC
Last Seen2026-08-27 05:06:03 UTC
Profile Built2026-08-29 05:50:32 UTC
Data FreshnessLive
Signal Types30
Total Observations33
🔍 30 signal types · 33 observations collected
This report is generated from 30+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 212.86.116.26

Who owns the IP address 212.86.116.26?

212.86.116.26 is registered to Vyacheslav Smyrnov. The address falls within the 212.86.116.0/24 network block. Registration is held at RIPE.

Where is 212.86.116.26 located?

Geolocation data places 212.86.116.26 in Kyiv, Kyiv City, Ukraine. The local time zone is Europe/Kyiv. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 212.86.116.26 malicious or safe?

212.86.116.26 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.

What is the hostname for 212.86.116.26?

The reverse DNS (PTR) record for 212.86.116.26 is dedicated.vsys.host. This hostname is not forward-confirmed, so it should be treated as a weak signal.

What ports are open on 212.86.116.26?

Responsive ports observed on 212.86.116.26 include 80, 443, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.

🏘️ Related IP Addresses

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.