IP Intelligence Briefing: 23.191.200.51
Date: 2026-06-16
---
**1. Core Profile**
- Risk Score: 66 (Moderate Risk)
- Ownership: Unredacted Inc (ASN 401401)
- Geolocation: Registered to New York, US (geoPlausible: False)
- Threat Indicators:
- Tor exit node activity detected
- DNSBL listing (1/8)
- Open services: HTTP (80), HTTPS (443)
- Network Role: Identified as a Tor Exit Node with no clear infrastructure type.
---
**2. Observation History**
- Recent Activity (Last 30 Days):
- 46 observations logged, with minimal risk (score: 0.15) as the primary signal.
- Connection failures noted (e.g., "connection_failed" for HTTPS).
- RTT anomalies: Geolocation suggests ~7,626km distance, but minimum possible RTT is 152.5ms (observed: 45ms), indicating potential spoofing or synthetic data.
- Threat Persistence: No long-term malicious activity detected (threatObservationCount: 1).
---
**3. Relationships & Network Context**
- Linked Entities:
- Same network: UNREDACTED-V4-01 (repeated 52 times in relationships).
- Subnet: 23.191.200.0/24 with high abuse density (100 neighbors, 99 medium/high risk).
- Subnet Risk:
- 99/100 neighbors classified as medium/high risk.
- 67 neighbors flagged for threat activity.
- Abuse density score: 0.5447 (high risk).
---
**4. Actions & Recommendations**
- Block Tor Exit Nodes: Given the Tor exit association, consider blocking this IP in firewalls (e.g., iptables: `iptables -A INPUT -s 23.191.200.51 -j DROP`).
- Monitor Subnet: The subnet has a high abuse density; prioritize monitoring related IPs for lateral movement or cluster-based attacks.
- Verify Geolocation: Investigate the geoPlausible discrepancy (false) and RTT anomalies to rule out spoofing or misconfigured systems.
- Check TLS Certificates: The certificate issuer/subject (CN=www.bke6dql6thafqep.com) appears synthetic; validate if this is a honeypot or misconfigured service.
---
Conclusion:
This IP is a Tor exit node with open web services, linked to a high-risk subnet. While it shows minimal risk in some signals, the Tor association and subnet abuse density warrant closer scrutiny. SOC teams should monitor for unusual traffic patterns and consider blocking Tor exit nodes to mitigate potential threat vectors.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Unredacted Inc |
| ASN | β |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | 2026-06-08T00:00:00+00:00 |
| Valid Until | 2026-09-04T00:00:00+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 88 days |
| Serial Number | 7CF8637351F37E43 |
| Thumbprint | 8105DF29234BB5DB4B85CBD60D2E4B70FABA9DAE |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 28% | 2 | 3 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 24% | 10 | 16 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-22 13:35:45 UTC |
| Last Seen | 2026-06-26 21:06:50 UTC |
| Profile Built | 2026-06-27 16:52:19 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 48 |
Full dossier details are available via our API.