# IP Intelligence Briefing: 57.129.91.235
## Executive Summary
IP address 57.129.91.235 operates as a Tor exit node hosted by OVH GmbH in Frankfurt am Main, Germany. The address carries a moderate risk score (59) and is flagged for Tor exit node activity with one DNSBL listing observed.
## Ownership and Geolocation
- ASN: 16276 (OVH GmbH)
- Organization: OVH GmbH
- Location: Frankfurt am Main, Hesse, Germany (DE)
- CIDR Block: 57.129.0.0/17
- Registration RIR: ARIN
## Threat Indicators
- Tor Exit Node: Confirmed (isTorExit: true)
- Threat Indicators: Tor exit indicators observed
- Blacklist Status: 1 DNSBL listing detected
- Known Campaigns: None identified
- Known Attacker Status: Not flagged
- Spam Source Status: Not flagged
## Network Services
- Open Ports: TCP/22 (SSH) - OpenSSH_9.2p1 Debian variant
- DNS Resolution: exit1.mit-security.at (forward confirmed)
- PTR Record: exit1.mit-security.at
- Email Authentication: SPF and DMARC records present
## Neighborhood Analysis
- Subnet: 57.129.91.235/24
- Subnet Classification: Mostly clean
- Abuse Density: 1
- Threat Siblings: 1 identified
- Control Plane: Route stable (isRouteStable: true), BGP prefix 57.129.0.0/17
## Historical Observations
- Total Observations: 52 signals recorded
- Risk Trend: Consistent moderate risk classification across observation period
- Operator Score: 0.5652 (Moderate)
- Threat Persistence: Not persistently malicious
- Ownership Changes: None observed
## Relationship Graph
- DNS Associations: exit1.mit-security.at
- Network Relationships: PCI-DE1 network segment
- Total Relationships: 256 identified entities
## Risk Assessment
The IP address presents moderate risk primarily due to its function as a Tor exit node. Tor exit nodes are commonly exploited for anonymity-based attacks, though the IP itself is not classified as a known attacker. The consistent moderate risk profile across historical observations indicates stable operational behavior without escalation to high-risk classification.
## Recommended Actions
- Monitoring: Monitor outbound connections from internal networks to this IP
- Egress Filtering: Consider blocking inbound connections to port 22 from this IP
- Threat Hunting: Investigate any connections to this IP for potential Tor-based traffic exfiltration attempts
- DNS Filtering: The hostname "exit1.mit-security.at" may warrant additional scrutiny for command-and-control patterns
## SOC Analyst Notes
While this IP is not actively malicious, its designation as a Tor exit node requires awareness for potential abuse scenarios. The .at domain extension on a German-housed IP suggests potential misconfiguration or repurposing of infrastructure. No active campaign correlation detected.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | OVH GmbH |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | 57.129.0.0/17 |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | exit1.mit-security.at |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | exit1.mit-security.at |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.2p1 Debian-2+deb12u10 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 20% | 2 | 3 |
| services | 12% | 2 | 2 |
| ownership | 19% | 3 | 4 |
| reputation | 28% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 22% | 12 | 18 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-22 13:35:40 UTC |
| Last Seen | 2026-06-28 19:17:14 UTC |
| Profile Built | 2026-06-29 07:20:32 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 52 |
Full dossier details are available via our API.