IPDebrief

78.17.93.70

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING: 78.17.93.70/32

Date: Current | Classification: Moderate Risk | Risk Score: 59/100

---

## EXECUTIVE SUMMARY

IP 78.17.93.70 is classified as a Tor exit node with moderate risk indicators. The address is associated with ASN 26832 (moula-world-llc) and exhibits Tor-related threat signatures. One blacklist listing was recorded. The IP presents moderate concern for defensive security teams due to its role as an anonymous traffic gateway.

---

## TECHNICAL PROFILE

Network Classification:

Open Services:

DNS Resolution:

---

## THREAT INDICATORS

IndicatorStatusSeverity
Tor Exit Node**Confirmed**Medium
Blacklist Listings1Low
DNSBL ListedYes (1 of 8)Low
Known AttackerNoNone
Spam SourceNoNone

Abuse Confidence: Score not available; classified as moderate risk based on Tor exit node classification.

---

## OBSERVATION HISTORY

Temporal analysis indicates this IP has not demonstrated persistent malicious behavior patterns.

---

## NETWORK NEIGHBORHOOD ANALYSIS

Subnet: 78.17.93.0/24

Identified Neighboring IPs (Risk Score 66):

All three neighbors share the same risk score (66) and authority score (50), indicating coordinated infrastructure within the subnet.

---

## RELATIONSHIP GRAPH

---

## DEFENSIVE RECOMMENDATIONS

Access Control

Monitoring

Recommended Firewall Rules

PlatformRule
iptables`iptables -A INPUT -s 78.17.93.70 -j DROP`
nftables`nft add rule inet filter input ip saddr 78.17.93.70 drop`
nginx`deny 78.17.93.70;`
pfSense`78.17.93.70/32`
Cloudflare WAFBlock rule with expression `ip.src eq 78.17.93.70`
AWS WAFAddresses: `78.17.93.70/32`

---

## ANALYST NOTES

This IP is actively classified as a Tor exit node and should be evaluated based on organizational tolerance for anonymous traffic. While not currently flagged as a known attacker, the Tor exit node classification warrants defensive measures. The subnet abuse density is low (0), suggesting this IP may be operating within a broader infrastructure that is not uniformly malicious.

Action Priority: MEDIUM — Implement enhanced logging and monitoring; consider blocking based on organizational policy regarding Tor traffic.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇺🇸 United States
RegionM
CityWaterford
Timezone—
Latitude42.69
Longitude-83.41

🏢 Ownership & Registration

OrganizationAbuse contact role object
ASNAS26832
Network Namemoula-world-llc
CIDR Block78.17.93.0/24
RIRRIPE
CountryUS
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR70.93.17.78.mtl6.servers.guru
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnames70.93.17.78.mtl4.servers.guru
70.93.17.78.mtl6.servers.guru

🔐 DNS Hygiene

Hygiene Score60% (Good)
SPFNot configured
DMARCPresent
FCrDNSNot verified
DNSSECValid
CAAPresent

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierTier 3 — Basic operator with some routing infrastructure
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Server—
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS26832
Network Prefix78.17.93.0/24
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
31%
26
routing
17%
23
services
24%
24
ownership
19%
34
reputation
22%
14
geolocation
24%
23
Overall23%1224
Coverage: 6/6 dimensions · Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) — 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Claimed geolocation contradicts RTT physics measurement

📅 Observation Timeline 🔄 Live

First Seen2026-07-16 15:02:03 UTC
Last Seen2026-09-03 22:27:13 UTC
Profile Built2026-09-03 22:40:36 UTC
Data FreshnessLive
Signal Types27
Total Observations40
🔍 27 signal types · 40 observations collected
This report is generated from 27+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 78.17.93.70

Who owns the IP address 78.17.93.70?

78.17.93.70 is registered to Abuse contact role object. The address falls within the 78.17.93.0/24 network block. Registration is held at RIPE.

Where is 78.17.93.70 located?

Geolocation data places 78.17.93.70 in Waterford, M, United States. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 78.17.93.70 malicious or safe?

78.17.93.70 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.

What is the hostname for 78.17.93.70?

The reverse DNS (PTR) record for 78.17.93.70 is 70.93.17.78.mtl6.servers.guru. This hostname is not forward-confirmed, so it should be treated as a weak signal.

🏘️ Related IP Addresses

Nearby addresses in 78.17.93.0/24

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.