IPDebrief

51.158.151.177

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 51.158.151.177/32

Classification: Moderate Risk (Score: 49/100)

Date Generated: [Current Date]

Primary Classification: Tor Exit Node

---

## Executive Summary

IP address 51.158.151.177 is identified as a Tor exit node operating from Paris, France (ASN 12876 / Mickael Marchand). The IP presents moderate risk (score 49) due to anonymous traffic characteristics inherent to Tor infrastructure. Current threat indicators show Tor exit node activity with 1 blacklist listing across 8 total DNSBL lists. The IP maintains a stable network role with web server services (HTTP/HTTPS) and SSH access enabled.

---

## Technical Profile

Network Ownership:

Geolocation:

DNS Resolution:

Active Services:

PortProtocolService
80TCPHTTP
443TCPHTTPS
22TCPSSH

TLS Certificate:

---

## Threat Indicators

Primary Risk Factor: Tor Exit Node Activity

Control Plane Metrics:

---

## Observation History Analysis

Total Observations: 56 signals recorded

Recent Signal Trends:

Temporal Analysis:

---

## Network Relationships & Infrastructure

Relationship Graph: 372 relationship entries identified

Key Associations:

Network Neighborhood (51.158.151.0/24):

---

## Recommended Security Actions

Access Control Recommendation:

Firewall Implementation Rules:

iptables:

```bash

iptables -A INPUT -s 51.158.151.177 -j DROP

```

nftables:

```bash

nft add rule inet filter input ip saddr 51.158.151.177 drop

```

nginx:

```nginx

deny 51.158.151.177;

```

pfSense:

```

51.158.151.177/32

```

Cloudflare WAF:

```json

{"description": "Block 51.158.151.177 โ€” IPDebrief risk score 49", "action": "block", "filter": {"expression": "ip.src eq 51.158.151.177"}}

```

AWS WAF:

```json

{"Addresses": ["51.158.151.177/32"], "Description": "IPDebrief risk 49"}

```

---

## SOC Analyst Assessment

Risk Level: Moderate (49/100)

Threat Characterization: This IP represents a Tor exit node, which is expected infrastructure behavior rather than active malicious activity. The moderate risk score reflects the anonymity characteristics of Tor exit nodes, which can be exploited by threat actors to mask their origin.

Recommended Response:

1. Implement traffic filtering if anonymous traffic violates organizational policies

2. Consider enhanced verification for traffic from this IP if business-critical services are exposed

3. Monitor for any changes in threat indicators or campaign activity

4. Note that the subnet shows low abuse density (0), indicating this IP is part of a relatively clean infrastructure segment

Campaign Correlation: No known campaigns or cert matches detected. Banner matches: 0. Correlated IPs: 0.

Action Priority: Medium severity. Implementation of blocking rules is recommended per organizational policy regarding Tor exit nodes, but business impact should be assessed before enforcement.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ณ๐Ÿ‡ฑ Netherlands
RegionIDF
CityParis
TimezoneEurope/Amsterdam
Latitude49.38
Longitude3.85

๐Ÿข Ownership & Registration

OrganizationMickael Marchand
ASNAS12876
Network Nameโ€”
CIDR Block51.158.128.0/17
RIRARIN
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR51-158-151-177.rev.poneytelecom.eu
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnames51-158-151-177.rev.poneytelecom.eu

๐Ÿ” DNS Hygiene

Hygiene Score60% (Good)
SPF1/2 domains
DMARC0/2 domains
FCrDNSVerified
DNSSECValid
CAANot configured
Domains Checked2 domains

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierTier 3 โ€” Basic operator with some routing infrastructure
Tor

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
443httpstcpโ€”
22sshtcp
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
Servernginx/1.24.0 (Ubuntu)
HTTP Titleโ€”
SSH VersionSSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16

๐Ÿ” TLS Certificate

๐Ÿ”’
CN=dedibox.esponde.net
Issued by CN=E8, O=Let's Encrypt, C=US
Self-signed: No
SANsdedibox.esponde.netdl.esponde.netinfiltro.esponde.netjoel.esponde.netkantuz.esponde.netmikel.esponde.netpensee-unique.esponde.netseafile.esponde.net
Valid From2026-05-28T05:00:21+00:00
Valid Until2026-08-26T05:00:20+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha384ECDSA
Validity Period89 days
Serial Number06AC6FE7B8554E9165DEB209B88C76AA25A5
Thumbprint754D512AE54B90A03B48BEBA87CDADC96009C146

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
31%
24
routing
20%
23
services
34%
23
ownership
27%
35
reputation
28%
13
geolocation
33%
23
Overall29%1221
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-22 13:35:43 UTC
Last Seen2026-06-28 19:26:10 UTC
Profile Built2026-06-29 07:28:46 UTC
Data FreshnessLive
Signal Types30
Total Observations57
๐Ÿ” 30 signal types ยท 57 observations collected
This report is generated from 30+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.