IP Intelligence Briefing: 66.78.40.91
Date: 2026-06-10
---
**1. Core Profile**
- Risk Score: 40 (Moderate Risk)
- Ownership:
- ASN: 21769 (Aokigahara SRL, US)
- Subnet: 66.78.40.0/24
- Geolocation: Wilmington, Delaware, US (no precise coordinates)
- Threat Indicators: Clean (no malicious indicators, blacklists, or campaigns).
- Network Role: Identified as a Tor Exit Node (provider: Tor Exit Nodes).
- DNS:
- Linked to `tor-exit-usa.bronk-ict.nl` (forward-resolved).
- SPF/DMARC records present but no email auth issues.
---
**2. Observation History**
- Recent Activity (2026-06-10):
- Consistent network prefix observations (AS21769, AS215659).
- Location data tied to Wilmington, DE, with a 2500km accuracy radius.
- Behavioral data: No direct honeypot hits, but flagged as a Tor exit node.
---
**3. Relationships**
- Key Associations:
- Same Network: 66.78.40.0/24 (Aokigahara SRL).
- DNS: `tor-exit-usa.bronk-ict.nl` (linked to the IP).
- Threat Context: No direct malicious relationships, but Tor exit nodes are often used for illicit traffic.
---
**4. Neighborhood Analysis**
- Subnet: 66.78.40.0/24 (abuse density: 0%).
- Neighbors:
- 66.78.40.42: Risk score 50 (higher than the IP).
- Subnet classification: "clean," but Tor exit nodes may introduce risk via third-party usage.
---
**5. Threat Narrative**
- Primary Risk: While the IP itself shows no direct malicious indicators, its role as a Tor exit node raises concerns. Tor networks are frequently used for covert communication, data exfiltration, and command-and-control (C2) activities.
- Neighbor Risk: The subnet contains one higher-risk IP (66.78.40.42), suggesting potential for lateral movement or shared infrastructure.
- Recommendations:
- Monitor traffic from this IP for unusual outbound connections (e.g., to known malicious domains).
- Investigate the Tor exit node's association with `tor-exit-usa.bronk-ict.nl` for potential misuse.
- Consider blocking or restricting traffic from the subnet due to the presence of higher-risk neighbors.
Conclusion: This IP is low-risk on its own but warrants scrutiny due to its Tor exit node role and subnet context. SOC teams should prioritize monitoring for indirect threats tied to Tor-based activities.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Aokigahara SRL |
| ASN | AS215659 |
| Network Name | NET-66-78-40-0-24 |
| CIDR Block | 66.78.40.0/24 |
| RIR | ARIN |
| Country | Romania |
| Abuse Contact | β |
π DNS Intelligence
| PTR | tor-exit-usa.bronk-ict.nl |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | tor-exit-usa.bronk-ict.nl |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 34% | 2 | 3 |
| routing | 61% | 2 | 39 |
| services | 15% | 2 | 2 |
| ownership | 37% | 3 | 9 |
| reputation | 20% | 1 | 2 |
| geolocation | 32% | 2 | 3 |
| Overall | 33% | 12 | 58 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-22 13:35:51 UTC |
| Last Seen | 2026-06-26 21:06:52 UTC |
| Profile Built | 2026-06-27 16:00:29 UTC |
| Data Freshness | Live |
| Signal Types | 27 |
| Total Observations | 97 |
Full dossier details are available via our API.