IP Intelligence Briefing: 5.255.118.218
Date: June 9, 2026
---
**Key Findings**
1. Threat Profile:
- Risk Score: 66 (Moderate Risk)
- Tor Exit Node: Confirmed. This IP is associated with Tor exit relays, which are known to be used for anonymizing malicious traffic, including C2 communications and data exfiltration.
- DNSBL Listing: Detected in 1 DNSBL (likely Spamhaus or similar), indicating potential abuse.
- Network Role: Classified as a Tor exit node, with no active services or hosting infrastructure.
2. Geolocation & Ownership:
- Location: Dronten, Flevoland, Netherlands (NL).
- ASN: 60404 (mnt-nl-theinfrastructuregroup-1, RIPE).
- Subnet: 5.255.118.218/24. Subnet abuse density is 0%, but 1 of 3 neighbors has a medium risk score.
3. Observation History:
- Recent Activity: Minimal risk signals observed over the past 30 days.
- Tor Exit Indicators: Persistent Tor exit activity detected, with no signs of recent changes in behavior.
4. Relationships & Neighbors:
- Network Relationships: Linked to the same network (TIG) and no high-risk entities.
- Neighbor Analysis:
- 1 neighbor (5.255.118.168) has a risk score of 65 (medium risk).
- 2 neighbors have low risk (scores 25 and 0).
---
**Actionable Insights**
- Monitor Traffic: Track outbound traffic from this IP, as Tor exit nodes are often used for covert malicious activities.
- Block/Restrict: Consider blocking this IP in firewall rules or WAFs, given its Tor association and DNSBL listing.
- Investigate Neighbors: Focus on the medium-risk neighbor (5.255.118.168) for potential lateral movement or shared infrastructure risks.
- Check for Campaigns: No known campaigns or malicious certificates linked to this IP, but continuous monitoring is advised.
---
Recommendation: This IP poses a moderate risk due to its role as a Tor exit node. While not actively malicious, its association with Tor and DNSBL listing warrants closer scrutiny. Prioritize blocking and monitoring to mitigate potential threats.
Tools Used: `ipdebrief_profile`, `ipdebrief_history`, `ipdebrief_relationships`, `ipdebrief_neighbors`.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | mnt-nl-theinfrastructuregroup-1 |
| ASN | AS60404 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | โ |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | 2026-05-13T00:00:00+00:00 |
| Valid Until | 2026-10-15T00:00:00+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 155 days |
| Serial Number | 00948B35A174EE6FA4 |
| Thumbprint | D9890EDC682048CC671FD35A65178A78C8838FE7 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 34% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 28% | 2 | 3 |
| ownership | 24% | 2 | 3 |
| reputation | 30% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 25% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-22 13:35:39 UTC |
| Last Seen | 2026-06-26 21:06:48 UTC |
| Profile Built | 2026-06-27 10:34:04 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 47 |
Full dossier details are available via our API.