# IP Intelligence Briefing: 85.11.167.137
## Executive Summary
IP 85.11.167.137 presents a moderate risk profile (score: 66/100) identified as a Tor exit node with confirmed anonymity service indicators. The address is associated with the TechTies-Network (ASN 197170) and is currently listed on one DNSBL with high-severity severity ratings.
## Profile Overview
- IP Address: 85.11.167.137/32
- Risk Score: 66/100 (Moderate Risk)
- Classification: Tor Exit Node / Single-Service Host
- ASN: 197170 (bg-sofcompany-1-mnt)
- Netname: TechTies-Network
- Geolocation: Netherlands (NL) / Sofia region
- Network Range: 85.11.167.0/24
- DNSBL Status: Listed on 1 of 8 threat feeds
- Open Services: TCP/22 (SSH)
## Threat Indicators
- Tor Exit Node: Confirmed active Tor exit node functionality
- Abuse Indicators: Blacklisted with high-severity severity
- Route Stability: Unstable (1 route change in 30-day window)
- Persistence: Non-persistent threat actor; no established malicious campaign correlation
## Network Context
The /24 subnet (85.11.167.0/24) exhibits mixed classification with an abuse density of 0.03. Of 34 sibling IPs, 7 are flagged as threats. Neighboring risk distribution shows:
- High Risk: 1 IP (85.11.167.183, score: 80)
- Medium Risk: 9 IPs
- Low Risk: 23 IPs
## Historical Activity
58 observations recorded. Recent activity (08-07-2026) shows consistent blacklist presence with maximum severity ratings. Operator score remains minimal (0.1739) indicating low-level routing infrastructure rather than sophisticated infrastructure.
## Recommended Actions
| Category | Action | Severity |
|---|---|---|
| Access Control | Implement enhanced verification for anonymous traffic | Medium |
| Monitoring | Increase logging verbosity for this IP; review recent activity | High |
| Firewall | Block at perimeter (iptables/nftables recommended) | High |
Sample Firewall Rules
```bash
# iptables
iptables -A INPUT -s 85.11.167.137 -j DROP
# nftables
nft add rule inet filter input ip saddr 85.11.167.137 drop
```
## Intelligence Assessment
This IP should be treated as a known Tor exit node with elevated abuse indicators. While not classified as persistently malicious, the combination of Tor exit functionality, blacklist presence, and unstable routing warrants defensive blocking at the network perimeter. Consider correlating with similar IPs in the /24 subnet for comprehensive mitigation.
Status: Active Threat Indicator | Priority: Medium-High | Recommendation: Block at firewall level with logging
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | bg-sofcompany-1-mnt |
| ASN | AS197170 |
| Network Name | TechTies-Network |
| CIDR Block | 85.11.167.0/24 |
| RIR | RIPE |
| Country | NL |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_10.0p2 Debian-7+deb13u4 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 61% | 2 | 27 |
| routing | 27% | 2 | 3 |
| services | 19% | 2 | 2 |
| ownership | 37% | 3 | 5 |
| reputation | 30% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 34% | 12 | 43 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-30 02:56:13 UTC |
| Last Seen | 2026-08-13 10:40:14 UTC |
| Profile Built | 2026-08-13 10:54:41 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 80 |
Full dossier details are available via our API.