IPDebrief

23.95.192.178

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING: 23.95.192.178

Classification: HIGH RISK

Date: 2026-07-28

Analyst: IPDebrief Intelligence Team

---

## EXECUTIVE SUMMARY

IP address 23.95.192.178 is a confirmed Tor exit node with an elevated risk score of 70/100. The address belongs to RackNerd LLC (ASN 36352) and exhibits characteristics consistent with anonymizing traffic proxy infrastructure. Defensive action is recommended pending correlation with additional threat intelligence.

---

## OWNERSHIP AND NETWORK ATTRIBUTES

AttributeValue
**Organization**RackNerd LLC
**ASN**36352
**CIDR Block**23.95.192.160/27
**Geolocation**Buffalo, NY, US
**Network Role**Web Server / Tor Exit Node

The IP is registered under CC-23-95-192-160-27 network block. Geolocation data shows Buffalo coordinates (42.89°N, -78.88°W) with geo-consensus enabled, though RTT validation flags a 6,108km distance discrepancy suggesting potential geolocation spoofing.

---

## THREAT INDICATORS

Primary Indicators

Network Classification

---

## NETWORK BEHAVIOR ANALYSIS

DNS Analysis

Service Exposure

PortProtocolServiceBanner
80TCPHTTP-
443TCPHTTPS-
22TCPSSHSSH-2.0-OpenSSH_10.0p2 Debian-7+deb13u4

TLS Certificate Analysis

---

## NEIGHBORHOOD CONTEXT

Subnet: 23.95.192.178/24

The /24 subnet shows mixed reputation with one threat-identified sibling.

---

## OBSERVATION HISTORY

Total Observations: 31 signals across monitoring period

Recent Key Findings (2026-07-28):

The IP shows recent Tor exit node classification with no evidence of persistent malicious campaign activity.

---

## RELATED ENTITIES

DNS Associations: Multiple hostname records pointing to mta181.ef92b778bafe771e.net

---

## DEFENSIVE RECOMMENDATIONS

Immediate Actions

1. Access Control: Consider enhanced verification for anonymous traffic from this IP

2. Monitoring: Increase logging verbosity and review recent activity from this source

3. Threat Severity: High (risk score 70/100)

Firewall Rule Implementation

PlatformRule
**iptables**`iptables -A INPUT -s 23.95.192.178 -j DROP`
**nftables**`nft add rule inet filter input ip saddr 23.95.192.178 drop`
**nginx**`deny 23.95.192.178;`
**pfSense**`23.95.192.178/32`
**Cloudflare WAF**Block with expression: `ip.src eq 23.95.192.178`
**AWS WAF**Addresses: `["23.95.192.178/32"]`

---

## ANALYST NOTES

This IP exhibits classic Tor exit node behavior. The combination of:

1. Explicit Tor exit node classification

2. Suspicious DNS hostname pattern

3. Elevated risk score (70/100)

4. Web server with SSH exposure

...warrants defensive blocking in most organizational contexts. However, correlation with internal threat intelligence and traffic analysis should precede permanent blocking to avoid potential false positives.

Recommendation: Block immediately pending further investigation.

---

*Report generated by IPDebrief Intelligence Platform*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇺🇸 United States
RegionNY
CityBuffalo
TimezoneAmerica/New_York
Latitude43.30
Longitude-74.97

🏢 Ownership & Registration

OrganizationRackNerd LLC
ASNAS36352
Network NameCC-23-95-192-160-27
CIDR Block23.95.192.160/27
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRmta181.ef92b778bafe771e.net
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesmta181.ef92b778bafe771e.net

🔐 DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierUnknown — Insufficient routing data to classify
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
80httptcp—
443httpstcp—
22sshtcpBanner detected
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
Server—
HTTP Title—

🔐 TLS Certificate

🔒
CN=www.syw7ztbnb32cxkg4ogq.net
Issued by CN=www.odnnxs22v75gv.com
Self-signed: No
SANsNone
Valid From2026-04-28T00:00:00+00:00
Valid Until2026-10-02T00:00:00+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period65 days

🛡️ Public Network Snapshot

Origin ASNAS36352
Network Prefix23.95.192.0/23
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
31%
26
routing
17%
23
services
33%
26
ownership
19%
34
reputation
23%
15
geolocation
20%
24
Overall24%1228
Coverage: 6/6 dimensions · Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) — 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Claimed geolocation contradicts RTT physics measurement

📅 Observation Timeline 🔄 Live

First Seen2026-07-17 12:38:37 UTC
Last Seen2026-09-10 12:22:50 UTC
Profile Built2026-09-10 12:30:42 UTC
Data FreshnessLive
Signal Types28
Total Observations42
🔍 28 signal types · 42 observations collected
This report is generated from 28+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 23.95.192.178

Who owns the IP address 23.95.192.178?

23.95.192.178 is registered to RackNerd LLC. The address falls within the 23.95.192.160/27 network block. Registration is held at ARIN.

Where is 23.95.192.178 located?

Geolocation data places 23.95.192.178 in Buffalo, NY, United States. The local time zone is America/New_York. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 23.95.192.178 malicious or safe?

23.95.192.178 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.

What is the hostname for 23.95.192.178?

The reverse DNS (PTR) record for 23.95.192.178 is mta181.ef92b778bafe771e.net. This hostname is not forward-confirmed, so it should be treated as a weak signal.

What ports are open on 23.95.192.178?

Responsive ports observed on 23.95.192.178 include 80, 443, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.

🏘️ Related IP Addresses

Nearby addresses in 23.95.192.160/27

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.