IPDebrief

45.95.169.119

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

IP Intelligence Briefing: 45.95.169.119

Date: 2026-06-09

---

**1. Core Risk Profile**

- Tor exit node activity detected.

- DNS association with `tor-exit-croatia.bronk-ict.nl` (linked to Tor infrastructure).

---

**2. Threat Observations**

- PTR hostname `tor-exit-croatia.bronk-ict.nl` resolved to the IP.

- SPF and DMARC records detected, but no email-related abuse indicators.

- Open ports: HTTP (80) and HTTPS (443).

- TLS certificate anomalies: Subject `CN=www.cnyi4zngoxsk.net` and issuer `CN=www.wabkalfs.com` (potentially spoofed).

- Subnet `45.95.169.0/24` has abuse density score 1 (low), but 1 active sibling IP (45.95.169.104) with risk score 70.

---

**3. Temporal Trends**

- 1 observation of Tor exit node behavior.

- 2 DNS resolution events (consistent with Tor exit node patterns).

- 1 connection failure attempt (HTTPS, fingerprinted as "connection_failed").

---

**4. Network Relationships**

- Same Network: `MAXKO-HOSTING-HR` (ASN 211619).

- DNS: `tor-exit-croatia.bronk-ict.nl` (linked to Tor infrastructure).

- Subnet `45.95.169.119/24` contains 2 IPs, 1 active (risk score 70).

---

**5. Recommendations**

- Flag Tor exit node traffic originating from this IP.

- Monitor DNS queries to `tor-exit-croatia.bronk-ict.nl` for potential command-and-control (C2) activity.

- Isolate traffic from this subnet (45.95.169.0/24) to mitigate lateral movement risks.

- Block all traffic from this IP using iptables/nftables rules.

- Consider AWS WAF or Cloudflare WAF rules to filter Tor-related traffic.

---

Conclusion:

This IP is associated with Tor exit node infrastructure, indicating potential use in anonymized or malicious traffic. While the subnet has low abuse density, the high risk score and Tor association necessitate immediate monitoring and network segmentation.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionUS-MA
CityBoston
TimezoneAmerica/New_York
Latitude45.47
Longitude16.39

🏒 Ownership & Registration

OrganizationDamir Flekac
ASNAS211619
Network Nameβ€”
CIDR Blockβ€”
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRtor-exit-croatia.bronk-ict.nl
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamestor-exit-croatia.bronk-ict.nl

πŸ” DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierTier 3 β€” Basic operator with some routing infrastructure
Tor

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpβ€”
443httpstcpβ€”
Closed Ports22, 25, 3389, 8080, 8443 (2 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
CN=www.cnyi4zngoxsk.net
Issued by CN=www.wabkalfs.com
Self-signed: No
SANsNone
Valid From2026-01-15T00:00:00+00:00
Valid Until2027-01-12T00:00:00+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period362 days
Serial Number7F116C420B2E6F16
Thumbprint2C2E29A8391BB7BFF614C501EEF6012083EFC15F

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
27%
24
routing
13%
11
services
26%
23
ownership
24%
23
reputation
26%
13
geolocation
19%
22
Overall23%1016
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) β€” 1 contradiction(s)
AttributionModerate (55%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Geo sources disagree on country: HR, US

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-22 13:35:44 UTC
Last Seen2026-06-26 21:06:50 UTC
Profile Built2026-06-27 17:03:54 UTC
Data FreshnessLive
Signal Types23
Total Observations52
πŸ” 23 signal types Β· 52 observations collected
This report is generated from 23+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.