IP Intelligence Briefing: 23.129.64.133
Date: 2026-06-12
---
**1. Core Profile**
- Risk Score: 70 (High Risk)
- Ownership:
- ASN: 396507
- Organization: Emerald Onion (Tor Exit Node)
- Geolocation: Seattle, WA, US (geo plausibility: False)
- Threat Indicators:
- Listed in 4/8 DNSBLs (high severity).
- Tor Exit Node (no direct malware indicators).
- Network Role:
- Provider: Tor Exit Network
- Services: HTTP/HTTPS (ports 80/443 open).
- TLS Certificate: Issued to `www.zcfdevldx.com`, subject `www.h2kkpgq3yyuwbbvx2.net`.
---
**2. Observation History**
- Recent Activity (30 Days):
- 42 Observations: 10 high-severity DNSBL listings, 3 operator risk assessments.
- Geo Validation Violation: RTT (79ms) inconsistent with 7,626km distance (min possible: 152.5ms).
- Stability: Route stable (BGP prefix: `23.129.64.0/24`).
---
**3. Relationships**
- Linked Entities:
- Same Network: 54 IPs (EMERALD-ONION-TOR1 subnet).
- Threat Associations: No direct campaign links, but 45/97 neighbors are high/medium risk.
- Control Plane:
- BGP Path: `6939 396507` (AS-History: 3267 days).
- DNSSEC: Valid.
- Route Stability: 0 changes in 30 days.
---
**4. Neighborhood Analysis**
- Subnet: `23.129.64.0/24` (abuse density: 10.4%).
- Neighbor Risk Distribution:
- High Risk: 10 IPs (avg. score: 66).
- Medium Risk: 86 IPs (avg. score: 55).
- Low Risk: 0 IPs.
- Notable Neighbors:
- `23.129.64.99`, `23.129.64.130`, `23.129.64.131` (all high/medium risk).
---
**5. Recommendations**
- Monitoring:
- Track traffic to/from this IP for anomalous behavior (e.g., C2 communications, data exfiltration).
- Monitor neighbors for lateral movement or network compromise.
- Mitigation:
- Consider blocking Tor exit nodes in firewall rules (if not required for legitimate use).
- Validate TLS certificates and enforce HSTS/HTTP/2 for services on ports 80/443.
- Investigation:
- Cross-reference with DNSBLs and threat feeds for additional context.
Note: This IP is part of a Tor exit network, which is often used for both legitimate anonymity and malicious activities. The geo plausibility discrepancy and DNSBL listings suggest potential misuse.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Emerald Onion |
| ASN | AS396507 |
| Network Name | β |
| CIDR Block | 23.129.64.0/24 |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | 2025-11-29T00:00:00+00:00 |
| Valid Until | 2026-11-08T23:59:59+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 344 days |
| Serial Number | 0097BF2E2B93E7013B |
| Thumbprint | ADB5CE25848FC9FEF61DD435EAD9A5727AE4BF28 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 43% | 2 | 5 |
| routing | 24% | 2 | 3 |
| services | 34% | 2 | 3 |
| ownership | 37% | 3 | 9 |
| reputation | 28% | 1 | 3 |
| geolocation | 34% | 2 | 3 |
| Overall | 33% | 12 | 26 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-22 13:35:50 UTC |
| Last Seen | 2026-06-26 21:06:52 UTC |
| Profile Built | 2026-06-27 16:05:00 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 59 |
Full dossier details are available via our API.