# IP Intelligence Briefing: 213.202.233.140
## Executive Summary
IP address 213.202.233.140 presents a Moderate Risk threat profile (risk score: 59) with confirmed Tor exit node activity and multiple blacklist listings. The IP belongs to WIIT AG NOC and is geolocated to Ühlingen-Birkendorf, Germany. SOC teams should monitor this IP for potential abuse of Tor infrastructure and related malicious activities.
---
## Ownership & Infrastructure
- ASN: 24961 (WIIT AG NOC)
- Organization: WIIT AG NOC
- Network: 213.202.192.0/18 (RIR: RIPE)
- Geolocation: Ühlingen-Birkendorf, Baden-Wurttemberg, Germany (DE)
- DNS PTR: srv20935.dus7.dedicated.server-hosting.expert
- Forward Resolution: Forward confirmed (1 hostname)
---
## Threat Indicators
- Primary Concern: Tor exit node activity detected
- Blacklist Status: Listed on 1 of 8 monitored DNSBLs
- Threat Indicators: Tor exit indicators observed
- Abuse Confidence: Evidence indicates Tor infrastructure usage
- Known Campaigns: None identified
- DNSBL Listings: 1 current listing
---
## Network Services
- Open Ports:
- TCP/80 (HTTP)
- TCP/443 (HTTPS)
- TCP/22 (SSH - OpenSSH_10.0p2 Debian)
- TLS Certificate: CN=www.cmsrl2pisrgrzu.com (subject: CN=www.vozkgeyjky.net)
- SSL Status: Non-self-signed certificate
---
## Risk History
- Observations: 72 historical signals recorded
- Recent Activity: Multiple high-severity blacklist listings detected on 2026-07-23 (08:57-10:52 UTC)
- Listings: 1 of 8 total blacklist checks triggered, with maximum severity rated "high"
- Threat Persistence: Single threat observation event (not persistently malicious)
- Operator Score: 0.4783 (Basic classification)
---
## Network Relationships
- Total Relationships: 293 associations
- DNS Associations: Multiple entries mapping to srv20935.dus7.dedicated.server-hosting.expert
- Infrastructure Type: Dedicated server hosting environment
---
## Neighborhood Analysis
- Subnet: 213.202.233.140/24
- Abuse Density: 1 (moderate)
- Classification: Mostly clean
- Threat Siblings: 1 identified
- Risk Distribution: Low threat density in immediate subnet
---
## Recommended Actions
1. Monitor Tor Exit Node Activity: Track outbound connections from this IP for potential abuse
2. Blacklist Monitoring: Maintain awareness of DNSBL listing status (1 of 8 lists)
3. Traffic Analysis: Inspect HTTPS traffic for suspicious patterns given Tor exit node classification
4. SSH Access: Review SSH connection logs for unauthorized access attempts
5. Certificate Analysis: Monitor TLS certificate usage for potential spoofing or abuse
---
## Conclusion
This IP represents a legitimate hosting infrastructure operating as a Tor exit node. While not inherently malicious, the Tor exit node designation creates elevated risk for abuse scenarios. SOC analysts should focus on monitoring outbound traffic patterns and blacklist status rather than blocking the IP outright. The single high-severity blacklist listing and Tor exit node status warrant continued observation.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | WIIT AG NOC |
| ASN | AS24961 |
| Network Name | DE-MYLOC-DUS-20021021 |
| CIDR Block | 213.202.192.0/18 |
| RIR | RIPE |
| Country | DE |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | srv20935.dus7.dedicated.server-hosting.expert |
| Forward Confirmed | Yes — FCrDNS verified |
| Forward Hostnames | srv20935.dus7.dedicated.server-hosting.expert |
🔐 DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Tier 3 — Basic operator with some routing infrastructure |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 443 | https | tcp | — |
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
CN=www.ntpl2yg6zqibjlmjyyp.net was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.| SANs | None |
| Valid From | 2026-02-19T00:00:00+00:00 |
| Valid Until | 2026-09-07T23:59:59+00:00 (expired) |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 200 days |
🛡️ Public Network Snapshot
| Origin ASN | AS24961 |
| Network Prefix | 213.202.192.0/18 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 60% | 2 | 22 |
| routing | 27% | 2 | 3 |
| services | 35% | 2 | 3 |
| ownership | 39% | 3 | 7 |
| reputation | 26% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 37% | 12 | 41 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-04 22:50:11 UTC |
| Last Seen | 2026-08-27 07:57:05 UTC |
| Profile Built | 2026-08-29 05:10:28 UTC |
| Data Freshness | Live |
| Signal Types | 27 |
| Total Observations | 30 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 213.202.233.140
Who owns the IP address 213.202.233.140?
213.202.233.140 is registered to WIIT AG NOC. The address falls within the 213.202.192.0/18 network block. Registration is held at RIPE.
Where is 213.202.233.140 located?
Geolocation data places 213.202.233.140 in Ühlingen-Birkendorf, Baden-Wurttemberg, Germany. The local time zone is Europe/Berlin. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 213.202.233.140 malicious or safe?
213.202.233.140 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 213.202.233.140?
The reverse DNS (PTR) record for 213.202.233.140 is srv20935.dus7.dedicated.server-hosting.expert. This hostname is forward-confirmed, meaning it resolves back to the same address.
What ports are open on 213.202.233.140?
Responsive ports observed on 213.202.233.140 include 80, 443, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.