IP Intelligence Briefing: 23.129.64.201
*Generated via IPDebrief tools: profile, history, relationships, neighbors, and actions.*
---
**1. Risk Profile**
- Risk Score: 70/100 (High Risk)
- Provider: Tor Exit Nodes (ASN 396507, Emerald Onion)
- Geolocation:
- Claimed: Seattle, WA, US (2500km accuracy radius)
- Validation: GeoPlausible = False (RTT mismatch: 82ms vs. expected 152.5ms for distance)
- Network Role: Tor Exit Node (classified as "Web Server" with HTTP/HTTPS services open).
---
**2. Threat Indicators**
- No Direct Threats: No indicators of spam, malware, or known attacker activity.
- TLS Certificate:
- Issuer: `CN=www.iovmxw57nyx7nqgy.com`
- Subject: `CN=www.proqt4gb3.net` (SANs not listed).
- BGP Analysis:
- Route stability: Stable (no recent changes).
- ASN 396507 (Emerald Onion) is linked to Tor infrastructure.
---
**3. Observation History**
- Recent Activity:
- 30-day history shows minimal risk (operator score 0.13) with no persistent malicious behavior.
- Geo validation violations suggest potential spoofing or misconfigured routing.
- Trend: No significant increases in risk or threat signals.
---
**4. Network Relationships**
- Subnet: 23.129.64.0/24 (96 sibling IPs).
- Abuse Density: 8.3% (low subnet-wide abuse).
- Neighbors: 8 IPs in the subnet share the same high-risk score (70), including:
- 23.129.64.99, 23.129.64.130β133 (all riskScore 70).
- Shared Network: Linked to EMERALD-ONION-TOR1 (Tor exit node network).
---
**5. Recommended Actions**
- Monitoring: Increase logging verbosity for traffic from this IP.
- Blocking:
- Firewall Rules:
```bash
iptables -A INPUT -s 23.129.64.201 -j DROP
nft add rule inet filter input ip saddr 23.129.64.201 drop
```
- Cloud/WAF:
- Cloudflare: `ip.src eq 23.129.64.201` (block).
- AWS WAF: Add `23.129.64.201/32` to a rule.
---
**6. Summary**
This IP is a Tor exit node associated with Emerald Onion, showing no direct malicious activity but elevated risk due to its Tor association and geo validation discrepancies. While the subnet has low abuse density, the IPβs high risk score warrants monitoring and blocking to mitigate potential risks tied to its Tor infrastructure role.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Emerald Onion |
| ASN | AS396507 |
| Network Name | β |
| CIDR Block | 23.129.64.0/24 |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | 2026-05-26T00:00:00+00:00 |
| Valid Until | 2026-07-14T23:59:59+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 49 days |
| Serial Number | 00827A65A251CFBE2A |
| Thumbprint | 936B921A34BDB6916460C1447435B1B0EF71B347 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 57% | 2 | 11 |
| routing | 24% | 2 | 3 |
| services | 30% | 2 | 3 |
| ownership | 37% | 3 | 9 |
| reputation | 28% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 34% | 12 | 32 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-22 13:35:50 UTC |
| Last Seen | 2026-06-26 21:06:52 UTC |
| Profile Built | 2026-06-27 16:04:59 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 65 |
Full dossier details are available via our API.