IP Intelligence Briefing: 23.129.64.151
Date: 2026-06-13
---
**1. Profile Summary**
- Risk Score: 70 (High Risk)
- Ownership: Emerald Onion (ASN 396507)
- Geolocation: Seattle, WA, US (inferred via geolocation signals)
- Threat Indicators:
- Tor exit node activity detected
- Listed in 4 DNSBLs (darklists)
- Network Role: Tor exit node (classified as "Web Server" with open ports 80/443)
- Services:
- TLS certificate with issuer *www.ifnwg2rhzdsta3zkb.com* and subject *www.rvprsyx2i2.net*
- No HTTP title or server banner observed
---
**2. Observation History**
- Recent Activity (Last 30 Days):
- Persistent signals (41 total observations) with confidence ranging 0.35β0.85.
- High-risk categorization in 4/8 DNSBL lists (e.g., Spamhaus, Project Honey Pot).
- BGP route stability confirmed; no recent route changes.
- Geolocation Consistency:
- Inferred as Seattle, WA, US (2500km accuracy radius).
- No geo-validation violations detected.
---
**3. Relationships & Network Context**
- Linked Entities:
- Same network: EMERALD-ONION-TOR1 (repeated 64x in relationships).
- No direct connections to known malicious organizations or domains.
- Subnet Analysis (23.129.64.0/24):
- Abuse Density: 47.42% (18 inherited risk points).
- High-Risk Neighbors: 11 IPs with β₯70 risk scores (e.g., 23.129.64.99, 23.129.64.130).
- Total Siblings: 97 IPs (96 active).
---
**4. Threat Assessment**
- Malicious Activity:
- Strong indicators of Tor exit node misuse (high-risk score, DNSBL listings).
- No direct evidence of active exploitation (e.g., malware, phishing).
- Persistence:
- Observed for 1 day (threatObservationCount: 1).
- No persistent malicious behavior detected.
---
**5. Recommended Actions**
- Monitoring:
- Continuously monitor for new connections or traffic anomalies.
- Track changes in DNSBL listings or BGP route stability.
- Network Segmentation:
- Consider isolating traffic from this subnet (23.129.64.0/24) if sensitive services are exposed.
- Threat Intelligence:
- Cross-reference with Tor exit node lists for correlation with other threats.
---
Conclusion:
23.129.64.151 is a high-risk Tor exit node associated with Emerald Onion, linked to multiple DNSBL listings. While no direct malicious activity is observed, its role as a Tor exit node and high-risk subnet neighbors warrant close monitoring. No immediate blocking is recommended unless further malicious behavior is detected.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Emerald Onion |
| ASN | AS396507 |
| Network Name | β |
| CIDR Block | 23.129.64.0/24 |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | 2026-05-01T00:00:00+00:00 |
| Valid Until | 2026-07-29T00:00:00+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 89 days |
| Serial Number | 0097F58D86517D7897 |
| Thumbprint | CBAEEB0D978B244EDC180A83C6C567335DC2E7B7 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 45% | 2 | 7 |
| routing | 24% | 2 | 3 |
| services | 34% | 2 | 3 |
| ownership | 37% | 3 | 9 |
| reputation | 28% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 33% | 12 | 28 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-22 13:35:50 UTC |
| Last Seen | 2026-06-26 21:06:52 UTC |
| Profile Built | 2026-06-27 16:07:15 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 59 |
Full dossier details are available via our API.