IPDebrief

67.219.109.141

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

IP Intelligence Briefing: 67.219.109.141

Date: 2026-06-09

---

**Key Findings**

1. Threat Profile:

- Risk Score: 59 (Moderate Risk)

- Threat Indicators: Identified as a Tor exit node with observed Tor exit traffic.

- Ownership: Registered to The Constant Company, LLC (AS20473) under ARIN.

- Geolocation: Geotagged to Victoria, Melbourne, Australia (but coordinates are unverified).

2. Network Behavior:

- Services: Open port 80 (HTTP) with no TLS certificate.

- Routing: BGP prefix 67.219.96.0/20, stable route with no recent changes.

- DNS: Linked to hostname tor-exit-au-42.project-privacy.com.au (forward and reverse DNS confirmed).

3. Temporal Trends:

- Observation History:

- Moderate risk signals detected over 72 observations (last 30 days).

- DNS validation anomalies (RTT mismatch for 16,430km distance).

- No persistent malicious activity or ownership changes.

4. Network Relationships:

- Subnet: 67.219.109.141/24 (abuse density: 0, "mostly clean").

- Connections: Linked to CONSTANT network and Tor exit node infrastructure.

5. Security Implications:

- Tor Exit Node: Potential entry point for malicious traffic; monitor for C2 communication or data exfiltration.

- DNS Anomalies: Unverified geolocation and RTT discrepancies may indicate spoofing or misconfigured infrastructure.

---

**Recommended Actions**

---

Summary: This IP is a Tor exit node operated by The Constant Company, LLC. While the subnet shows low abuse density, its association with Tor and DNS anomalies warrants closer scrutiny. SOC teams should prioritize monitoring for suspicious activity related to its Tor infrastructure.

Tools Used: `ipdebrief_profile`, `ipdebrief_history`, `ipdebrief_relationships`, `ipdebrief_neighbors`.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionVictoria
CityMelbourne
Timezoneβ€”
Latitude-37.82
Longitude144.97

🏒 Ownership & Registration

OrganizationThe Constant Company, LLC
ASNAS20473
Network Nameβ€”
CIDR Block67.219.96.0/20
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRtor-exit-au-42.project-privacy.com.au
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamestor-exit-au-42.project-privacy.com.au

πŸ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting β€” Infrastructure provider without advanced routing
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
24
routing
17%
23
services
24%
23
ownership
31%
39
reputation
26%
13
geolocation
27%
23
Overall25%1225
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) β€” 1 contradiction(s)
AttributionModerate (55%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Claimed geolocation contradicts RTT physics measurement

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-22 13:35:49 UTC
Last Seen2026-06-28 19:31:14 UTC
Profile Built2026-06-29 01:33:31 UTC
Data FreshnessLive
Signal Types30
Total Observations37
πŸ” 30 signal types Β· 37 observations collected
This report is generated from 30+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.