IPDebrief

31.14.40.92

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 31.14.40.92/32

## Executive Summary

IP 31.14.40.92 is identified as a Tor exit node with a moderate risk score of 59/100. The address belongs to Romanian-based infrastructure (ASN 19624, Andi Cocei) and is currently listed on one blacklist with high severity. No active services are detected on the host.

## Risk Assessment

MetricValue
Risk Score59 (Moderate)
Abuse Density0 (Subnet-level)
Blacklist Count1 (High severity)
Total Lists8
ClassificationTor Exit Node

## Technical Profile

## Threat Indicators

## Historical Observations

Recent signal history indicates:

## Network Context

## Recommended Actions

SystemRecommended Action
iptables`iptables -A INPUT -s 31.14.40.92 -j DROP`
nftables`nft add rule inet filter input ip saddr 31.14.40.92 drop`
nginx`deny 31.14.40.92;`
Cloudflare WAFBlock IP 31.14.40.92/32
AWS WAFAdd 31.14.40.92/32 to deny list

## Operational Guidance

The IP should be blocked at perimeter controls due to confirmed Tor exit node classification and blacklist presence. No immediate threat to infrastructure integrity detected, but enhanced logging recommended for any observed traffic patterns. The subnet remains largely clean—no adjacent IP risk correlation observed.

*Analysis based on IPDebrief intelligence platform data. Verify with additional context before implementing blocking rules.*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇷🇴 Romania
Region—
City—
TimezoneEurope/Bucharest
Latitude45.94
Longitude24.97

🏢 Ownership & Registration

OrganizationAndi Cocei
ASNAS19624
Network NameRO-DATAROOM-20110418
CIDR Block31.14.40.0/23
RIRRIPE
CountryRO
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRlocalhost
Forward ConfirmedYes — FCrDNS verified
Forward Hostnamesmail.zkmail.org

🔐 DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierTier 3 — Basic operator with some routing infrastructure
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Server—
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS19624
Network Prefix31.14.40.0/23
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
31%
24
routing
32%
23
services
30%
23
ownership
40%
35
reputation
26%
13
geolocation
35%
23
Overall32%1221
Coverage: 6/6 dimensions · Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

📅 Observation Timeline 🔄 Live

First Seen2026-07-07 12:23:55 UTC
Last Seen2026-08-26 21:31:20 UTC
Profile Built2026-08-29 07:27:07 UTC
Data FreshnessLive
Signal Types28
Total Observations31
🔍 28 signal types · 31 observations collected
This report is generated from 28+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 31.14.40.92

Who owns the IP address 31.14.40.92?

31.14.40.92 is registered to Andi Cocei. The address falls within the 31.14.40.0/23 network block. Registration is held at RIPE.

Where is 31.14.40.92 located?

Geolocation data places 31.14.40.92 in Romania. The local time zone is Europe/Bucharest. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 31.14.40.92 malicious or safe?

31.14.40.92 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.

What is the hostname for 31.14.40.92?

The reverse DNS (PTR) record for 31.14.40.92 is localhost. This hostname is forward-confirmed, meaning it resolves back to the same address.

🏘️ Related IP Addresses

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.