IPDebrief

45.137.70.158

IP Intelligence Dossier
Your IP: 216.73.217.135
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

IP Intelligence Briefing: 45.137.70.158

*Generated via IPDebrief tools (profile, history, relationships, and neighborhood analysis)*

---

**1. Risk Profile**

- Identified as a Tor exit node (potential entry point for malicious traffic).

- Listed in 1 DNSBL (DNS-based blackhole list).

- No known attacker campaigns or spam sources.

- Registered to DATALIX-MNT (ASN 203446) under ARIN.

- Geolocation: Frankfurt am Main, Germany (Hesse region).

- Classified as a Tor exit node (single-service host).

- No cloud, CDN, or residential indicators.

---

**2. Observation History**

- Consistent Tor exit node activity (1 observation).

- No changes in ownership or threat signals.

- Abuse Confidence Score: Not available.

- First observed in August 2022 (1412 days active).

- No persistent malicious behavior detected.

---

**3. Relationships**

- Associated with Luxvps (network provider).

- No direct links to domains, certificates, or organizations.

- Part of 45.137.70.0/24.

- No direct sibling IPs identified (neighborhood data empty).

---

**4. Neighborhood Analysis**

- No neighboring IPs found in the /24 subnet.

- No shared risk indicators with surrounding IPs.

---

**5. Actionable Intelligence**

- Monitor Tor exit traffic from this IP for anomalous patterns (e.g., C2 communications, data exfiltration).

- Block or restrict SSH access (port 22) unless explicitly required.

- Investigate the Luxvps network for potential ties to malicious infrastructure.

- Ensure DNSSEC validation is enforced for subnets in this region.

```bash

# iptables: Block Tor exit node

iptables -A INPUT -s 45.137.70.158 -p tcp --dport 22 -j DROP

```

---

Conclusion: This IP is a Tor exit node with moderate risk due to its association with Tor and a DNSBL listing. While the subnet is otherwise clean, its role as a Tor node warrants closer monitoring for potential misuse.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฉ๐Ÿ‡ช Germany
RegionHesse
CityFrankfurt am Main (Innenstadt I)
TimezoneEurope/Berlin
Latitude51.17
Longitude10.45

๐Ÿข Ownership & Registration

OrganizationDATALIX-MNT
ASNAS203446
Network Nameโ€”
CIDR Block45.137.70.0/24
RIRARIN
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR158.70.137.45.in-addr.arpa
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnames158.70.137.45.in-addr.arpa

๐Ÿ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeSingle-Service Host
Network TierTier 3 โ€” Basic operator with some routing infrastructure
Tor

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
22sshtcp
Closed Ports25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”
SSH VersionSSH-2.0-OpenSSH_9.2p1 Debian-2+deb12u10

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
38%
25
routing
24%
23
services
12%
22
ownership
37%
37
reputation
26%
13
geolocation
30%
23
Overall27%1223
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-10 16:14:36 UTC
Last Seen2026-06-26 21:06:52 UTC
Profile Built2026-06-27 15:50:17 UTC
Data FreshnessLive
Signal Types27
Total Observations60
๐Ÿ” 27 signal types ยท 60 observations collected
This report is generated from 27+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.