IPDebrief

5.255.105.87

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 5.255.105.87/32

## Executive Summary

IP address 5.255.105.87 is classified as High Risk (Risk Score: 70/100) and operates as a Tor Exit Node originating from The Infrastructure Group (TIG) network in Dronten, Netherlands. This IP presents elevated threat indicators consistent with anonymized traffic sources and should be treated with enhanced scrutiny.

## Technical Profile

Ownership & Infrastructure

AttributeValue
ASN60404
Organizationmnt-nl-theinfrastructuregroup-1 (TIG)
CIDR Block5.255.105.0/24
RIRRIPE
Registration DateNot available
LocationDronten, Flevoland, Netherlands
TimezoneEurope/Amsterdam

Network Classification

Threat Indicators

DNS & Hostname Analysis

Services Exposed

PortProtocolServiceBanner
22TCPSSHSSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18

Control Plane Data

## Neighborhood Analysis (5.255.105.0/24)

## Observation History (30 Records)

Recent signal observations indicate:

The IP shows limited persistence and no evidence of long-term malicious campaign activity.

## Relationships Graph

## Recommended Actions

Access Control

Monitoring

Firewall Rules

```bash

# iptables

iptables -A INPUT -s 5.255.105.87 -j DROP

# nftables

nft add rule inet filter input ip saddr 5.255.105.87 drop

# nginx

deny 5.255.105.87;

# pfSense

5.255.105.87/32

# Cloudflare WAF

{"description":"Block 5.255.105.87 โ€” IPDebrief risk score 70","action":"block","filter":{"expression":"ip.src eq 5.255.105.87"}}

# AWS WAF

{"Addresses":["5.255.105.87/32"],"Description":"IPDebrief risk 70"}

```

## Intelligence Assessment

This IP address functions as a Tor exit node, providing anonymity to users accessing the internet through the Tor network. The presence of SSH service and Tor exit node functionality indicates potential use for:

The moderate-to-high risk score (70/100) combined with Tor exit node status warrants defensive measures. However, the IP is not persistently malicious, suggesting episodic rather than campaign-based activity.

SOC Recommendation: Implement the recommended firewall rules and enable enhanced logging for traffic from this subnet. Consider implementing behavioral analysis to distinguish between legitimate privacy users and malicious actors. Monitor for correlation with other threat indicators before taking blocking action.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ณ๐Ÿ‡ฑ Netherlands
RegionFlevoland
CityDronten
TimezoneEurope/Amsterdam
Latitude52.13
Longitude5.29

๐Ÿข Ownership & Registration

Organizationmnt-nl-theinfrastructuregroup-1
ASNAS60404
Network NameTIG
CIDR Block5.255.105.0/24
RIRRIPE
CountryNL
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRnetwork.vps.75746359.exit
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesnetwork.vps.75746359.exit

๐Ÿ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeSingle-Service Host
Network TierTier 3 โ€” Basic operator with some routing infrastructure
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
22sshtcp
Closed Ports25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
59%
221
routing
32%
34
services
34%
23
ownership
37%
35
reputation
26%
13
geolocation
35%
23
Overall37%1339
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (65%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-07-22 16:19:09 UTC
Last Seen2026-08-13 11:40:53 UTC
Profile Built2026-08-13 12:35:38 UTC
Data FreshnessLive
Signal Types27
Total Observations78
๐Ÿ” 27 signal types ยท 78 observations collected
This report is generated from 27+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.