# IP Intelligence Briefing: 5.255.105.87/32
## Executive Summary
IP address 5.255.105.87 is classified as High Risk (Risk Score: 70/100) and operates as a Tor Exit Node originating from The Infrastructure Group (TIG) network in Dronten, Netherlands. This IP presents elevated threat indicators consistent with anonymized traffic sources and should be treated with enhanced scrutiny.
## Technical Profile
Ownership & Infrastructure
| Attribute | Value |
|---|---|
| ASN | 60404 |
| Organization | mnt-nl-theinfrastructuregroup-1 (TIG) |
| CIDR Block | 5.255.105.0/24 |
| RIR | RIPE |
| Registration Date | Not available |
| Location | Dronten, Flevoland, Netherlands |
| Timezone | Europe/Amsterdam |
Network Classification
- Service Purpose: Single-Service Host
- Infrastructure Type: Tor Exit Node
- Connection Type: Not applicable
- Cloud/CDN/VPN: No
- Hosting/Residential/Mobile: No
- Bogon: No
Threat Indicators
- Primary Indicator: Tor exit indicators observed
- Blacklist Count: 1
- DNSBL Listed: 1 of 8 total lists
- Known Campaigns: None
- Is Known Attacker: No
- Is Spam Source: No
- Is Tor Exit: Yes
DNS & Hostname Analysis
- PTR Hostnames: network.vps.75746359.exit
- Forward Confirmed: No
- Hosted Domains: None
- Forward Resolution Count: 1
Services Exposed
| Port | Protocol | Service | Banner |
|---|---|---|---|
| 22 | TCP | SSH | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18 |
Control Plane Data
- Origin ASN: 60404
- BGP Prefix: 5.255.96.0/19
- AS Path: 6939 60404
- RPKI State: Not available
- Route Changes (30d): 1
- Route Stability: Not stable
- DNSSEC Valid: Yes
- Operator Score: 0.1304 (Minimal)
## Neighborhood Analysis (5.255.105.0/24)
- Abuse Density: 1
- Classification: mostly_clean
- Total Siblings: 2
- Active Siblings: 2
- Threat Siblings: 2
- Inherited Risk: 5
- Notable Neighbor: 5.255.105.182 (Risk Score: 59)
## Observation History (30 Records)
Recent signal observations indicate:
- Route Stability: Minimal concerns
- Operator Score: 0.1304 (Minimal)
- Ownership Changes: 0
- Threat Persistence Days: 0
- Is Persistently Malicious: No
- Threat Observation Count: 1
The IP shows limited persistence and no evidence of long-term malicious campaign activity.
## Relationships Graph
- Same Network: TIG (multiple network-level associations)
- DNS Association: network.vps.75746359.exit (multiple hostname mappings)
## Recommended Actions
Access Control
- Action: Consider enhanced verification for anonymous traffic
- Reason: Tor exit indicators observed
- Severity: Medium
Monitoring
- Action: Increase logging verbosity and review recent activity from this IP
- Reason: Elevated risk score (70/100)
- Severity: High
Firewall Rules
```bash
# iptables
iptables -A INPUT -s 5.255.105.87 -j DROP
# nftables
nft add rule inet filter input ip saddr 5.255.105.87 drop
# nginx
deny 5.255.105.87;
# pfSense
5.255.105.87/32
# Cloudflare WAF
{"description":"Block 5.255.105.87 โ IPDebrief risk score 70","action":"block","filter":{"expression":"ip.src eq 5.255.105.87"}}
# AWS WAF
{"Addresses":["5.255.105.87/32"],"Description":"IPDebrief risk 70"}
```
## Intelligence Assessment
This IP address functions as a Tor exit node, providing anonymity to users accessing the internet through the Tor network. The presence of SSH service and Tor exit node functionality indicates potential use for:
- Anonymized command and control communications
- Privacy-focused but potentially malicious traffic
- Legitimate privacy use cases (context-dependent)
The moderate-to-high risk score (70/100) combined with Tor exit node status warrants defensive measures. However, the IP is not persistently malicious, suggesting episodic rather than campaign-based activity.
SOC Recommendation: Implement the recommended firewall rules and enable enhanced logging for traffic from this subnet. Consider implementing behavioral analysis to distinguish between legitimate privacy users and malicious actors. Monitor for correlation with other threat indicators before taking blocking action.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | mnt-nl-theinfrastructuregroup-1 |
| ASN | AS60404 |
| Network Name | TIG |
| CIDR Block | 5.255.105.0/24 |
| RIR | RIPE |
| Country | NL |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | network.vps.75746359.exit |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | network.vps.75746359.exit |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 59% | 2 | 21 |
| routing | 32% | 3 | 4 |
| services | 34% | 2 | 3 |
| ownership | 37% | 3 | 5 |
| reputation | 26% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 37% | 13 | 39 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (65%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-22 16:19:09 UTC |
| Last Seen | 2026-08-13 11:40:53 UTC |
| Profile Built | 2026-08-13 12:35:38 UTC |
| Data Freshness | Live |
| Signal Types | 27 |
| Total Observations | 78 |
Full dossier details are available via our API.