IP INTELLIGENCE BRIEFING: 62.171.137.169/32
CLASSIFICATION: Moderate Risk โ Tor Exit Node Infrastructure
EXECUTIVE SUMMARY
IP 62.171.137.169 is identified as a Tor exit node located in Nuremberg, Germany (AS51167, Johannes Selg). The IP carries a moderate risk score of 49 and is flagged with Tor exit indicators, with one DNSBL listing. No open services were detected during reconnaissance, with the connection classified as "Firewalled / No Services."
TECHNICAL PROFILE
- ASN: 51167 | Organization: Johannes Selg
- Geolocation: Nuremberg, Germany (DE)
- BGP Prefix: 62.171.136.0/23
- PTR Record: vmi343398.contaboserver.net
- DNS Status: Forward confirmed, no SPF/DMARC records
- Network Role: Tor Exit Nodes (confirmed)
THREAT INDICATORS
- Tor Exit Node: Confirmed (isTorExit: true)
- Blacklist Status: 1 DNSBL listing
- Abuse Confidence: Moderate (risk score 49)
- Known Campaigns: None detected
- Known Attacker: False
- Spam Source: False
NETWORK NEIGHBORHOOD ANALYSIS
The /24 subnet (62.171.137.169/24) shows an abuse density of 0, classified as "mostly_clean." One neighboring IP (62.171.137.146) was identified with a risk score of 25 and authority score of 60. The subnet contains 2 active sibling IPs with 2 threat siblings.
HISTORICAL OBSERVATIONS
Forty-seven total observations recorded. Recent signal analysis (2026-06-26 through 2026-06-27) indicates minimal threat activity across multiple observation windows. The IP is not classified as persistently malicious.
NETWORK RELATIONSHIPS
The IP maintains 324 recorded relationships with strong associations to the CONTABO network infrastructure. DNS associations link to vmi343398.contaboserver.net. Multiple same-network relationships confirmed.
RECOMMENDED ACTIONS
1. Allow with monitoring: As a Tor exit node with no active services, the IP poses low direct exploitation risk but may be used for anonymization.
2. Monitor for abuse patterns: Track outbound connections for potential command-and-control or data exfiltration activity.
3. No immediate blocking required: The IP is not flagged as a known attacker or spam source.
4. Review firewall rules: Ensure egress filtering is in place if the receiving environment requires it.
ANALYST NOTES
The IP's classification as a Tor exit node is the primary risk factor. While not malicious in itself, Tor exit nodes are commonly abused for various purposes. The lack of open services and minimal historical threat activity suggests this instance is operating as expected within the Tor network.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Johannes Selg |
| ASN | AS51167 |
| Network Name | โ |
| CIDR Block | 62.171.136.0/23 |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vmi343398.contaboserver.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | vmi343398.contaboserver.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 20% | 2 | 3 |
| services | 12% | 2 | 2 |
| ownership | 19% | 3 | 4 |
| reputation | 28% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 23% | 12 | 19 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-22 13:35:40 UTC |
| Last Seen | 2026-06-28 19:16:36 UTC |
| Profile Built | 2026-06-29 07:20:32 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 51 |
Full dossier details are available via our API.