IP Intelligence Briefing: 64.190.76.10/32
*Generated via IPDebrief Threat Intelligence Platform*
---
**Core Profile**
- Risk Score: 66 (Moderate Risk)
- Threat Indicators:
- Identified as a Tor exit node (confirmed via DNS and geolocation anomalies).
- No known malware campaigns or spam sources linked.
- Geolocation:
- Reported as Italy (IT), but geo-validation flags inconsistencies:
- RTT (Round-Trip Time) of 112ms conflicts with 7,158km distance (minimum expected: 143ms).
- Coordinates suggest Georgia (region) but city is listed as "Decatur" (likely spoofed).
- Network Role:
- Tor exit node (BGP path: 6939 64445 214094).
- No active services or TLS certificates detected.
---
**Observation History**
- Last 30 Days:
- Consistent signal observation (34 total records).
- Stability score: 0.4783 (Basic operator risk score).
- No significant changes in threat or network behavior.
- Key Findings:
- Tor exit node activity has persisted without notable fluctuations.
- Geo-validation anomalies persist, suggesting potential spoofing or misattribution.
---
**Relationships & Context**
- Linked Entities:
- DNS: Resolves to `stracchino.exit.osservatorionessuno.org` (Tor exit node).
- Network: Associated with OSSERVATORIO-NESSUNO (ASN 214094).
- Subnet: 64.190.76.0/24 (abuse density: 14.3%).
- Neighbor Analysis:
- Subnet contains 1 high-risk neighbor (64.190.76.2, risk score 80) and 6 medium-risk IPs.
- Overall subnet classification: Clean but with elevated risk in specific IPs.
---
**Recommended Actions**
1. Block Tor Exit Nodes:
- Apply firewall rules to block traffic from Tor exit nodes (e.g., `iptables -A INPUT -s 64.190.76.0/24 -j DROP`).
2. Monitor Subnet:
- Track high-risk neighbors (e.g., 64.190.76.2) for suspicious activity.
3. Verify Geolocation:
- Investigate geo-validation discrepancies to confirm IP authenticity.
4. DNS Monitoring:
- Watch for DNS requests to `osservatorionessuno.org` or related domains.
---
Conclusion:
The IP is a Tor exit node with moderate risk, linked to a suspicious network and DNS entity. While the subnet is largely clean, the presence of high-risk neighbors and geo-validation anomalies warrants further investigation. Prioritize blocking Tor traffic and monitoring associated networks for potential malicious activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Admin |
| ASN | AS214094 |
| Network Name | โ |
| CIDR Block | 64.190.76.0/24 |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | stracchino.exit.osservatorionessuno.org |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | stracchino.exit.osservatorionessuno.org |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 27% | 2 | 3 |
| services | 15% | 2 | 2 |
| ownership | 27% | 3 | 4 |
| reputation | 26% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 25% | 12 | 19 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-22 13:35:43 UTC |
| Last Seen | 2026-06-26 21:06:49 UTC |
| Profile Built | 2026-06-27 17:16:34 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 53 |
Full dossier details are available via our API.