## INTELLIGENCE BRIEFING: 80.251.153.113/32
Classification: Tor Exit Node Infrastructure
Risk Level: Moderate (59/100)
Organization: Amarutu Technology Ltd (ASN 206264)
Location: Amsterdam, Netherlands (RIPE)
Network Block: 80.251.152.0/23
Executive Summary
IP 80.251.153.113 operates as a confirmed Tor exit node under Amarutu Technology Ltd infrastructure. The IP is actively listed on 8 DNS blacklists with high severity ratings and has been observed in threat feed databases. This is expected operational behavior for a Tor relay node.
Risk Assessment
- Overall Risk Score: 59 (Moderate Risk)
- Primary Threat Indicator: Tor exit node functionality confirmed
- Blacklist Status: Listed on 8 DNS blacklist sources
- Campaign Association: No active campaigns or threat intelligence matches
- Known Attacker Classification: FALSE
Technical Observations
Network Characteristics:
- ASN 206264 (Amarutu Technology Ltd)
- Route origin: 80.251.153.0/24
- BGP path: 2914 206264
- RPKI state: Valid
- Operator score: 0.2609 (Basic tier)
Geolocation:
- Country: Netherlands (NL)
- City: Amsterdam
- Region: North Holland
- Timezone: Europe/Amsterdam
- Geo consensus: Validated across multiple sources
DNS and Service Status:
- No forward DNS resolution confirmed
- No reverse PTR records
- No open services detected (Firewalled / No Services)
- No TLS certificates or hosted domains
Historical Trend Analysis
The IP has accumulated 59 signal observations with persistent threat indicators. Recent observations (August 11, 2026) show:
- Multiple blacklist listings with high severity ratings
- Consistent operator scoring at 0.2609
- Route stability changes observed over the past 30 days (1 route change)
- DNSSEC validation confirmed
The threat observation pattern indicates sustained operational activity as a Tor exit node rather than emerging malicious behavior.
Network Context
Subnet Analysis (80.251.153.0/24):
- Abuse density: 0 (mostly clean classification)
- Active sibling IPs: 1 (the target IP itself)
- Threat siblings: 1
- No high-risk adjacent IPs detected in the /24
Relationship Graph:
- 134 network relationships identified
- All relationships classified as "Same Network" (SC-AMARUTU-20051118)
- Indicates centralized Tor relay infrastructure
Recommended Actions
For Network Defenders:
1. Allow Traffic: This is legitimate Tor infrastructure. Blocking will disrupt legitimate privacy-preserving traffic.
2. Monitor for Abuse: While the IP itself is not a known attacker, monitor for:
- Unusual outbound connection patterns from your network to this IP
- Potential abuse of Tor exit node for C2 communications
- Spam or phishing campaigns originating through this exit node
3. Firewall Configuration: No blocking required. If deployment, consider:
- Rate limiting outbound connections to this IP
- Monitoring for anomalous traffic patterns
4. Threat Intelligence Context:
- This IP belongs to Amarutu's Tor relay infrastructure
- Known operator of Tor exit nodes
- Expected to appear on security-focused blacklists
SOC Analyst Guidance:
- Flag connections to this IP as "Tor Exit Node - Monitor"
- Do not automatically block or alert on traffic to/from this IP
- Monitor for indicators of compromise in outbound sessions using this destination
- Correlate with other Amarutu Technology (206264) infrastructure for comprehensive visibility
Conclusion
This IP is confirmed Tor exit node infrastructure operating within Amarutu Technology's Netherlands-based relay network. The moderate risk score reflects standard Tor exit node behavior rather than active malicious activity. No immediate defensive action required beyond standard monitoring and awareness.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Amarutu Technology Ltd |
| ASN | AS206264 |
| Network Name | SC-AMARUTU-20051118 |
| CIDR Block | 80.251.152.0/23 |
| RIR | RIPE |
| Country | NL |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 — Basic operator with some routing infrastructure |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS206264 |
| Network Prefix | 80.251.153.0/24 |
| Route mapping | Found |
| RPKI Status | Valid |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 6 |
| routing | 17% | 2 | 3 |
| services | 17% | 2 | 3 |
| ownership | 24% | 3 | 6 |
| reputation | 22% | 1 | 6 |
| geolocation | 20% | 2 | 4 |
| Overall | 21% | 12 | 28 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-10 14:25:08 UTC |
| Last Seen | 2026-09-14 05:16:27 UTC |
| Profile Built | 2026-09-14 05:18:54 UTC |
| Data Freshness | Live |
| Signal Types | 28 |
| Total Observations | 46 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 80.251.153.113
Who owns the IP address 80.251.153.113?
80.251.153.113 is registered to Amarutu Technology Ltd. The address falls within the 80.251.152.0/23 network block. Registration is held at RIPE.
Where is 80.251.153.113 located?
Geolocation data places 80.251.153.113 in Amsterdam, North Holland, Netherlands. The local time zone is Europe/Amsterdam. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 80.251.153.113 malicious or safe?
80.251.153.113 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.