# IP Intelligence Briefing: 87.121.52.101/32
Classification: MODERATE RISK — Tor Exit Node Infrastructure
Date: 2026-08-10
Risk Score: 59/100
## Executive Summary
IP 87.121.52.101 is identified as a Tor exit node hosting web services (HTTP/HTTPS) and SSH. The IP exhibits moderate-risk characteristics with Tor exit node indicators, multiple DNSBL listings, and recent blacklist activity. The IP resides in Bulgaria under ASN 34224 (Hrisian Petkov/VPSBG).
## Technical Profile
| Attribute | Value |
|---|---|
| **IP Address** | 87.121.52.101/32 |
| **Country** | BG (Bulgaria) |
| **ASN** | 34224 |
| **Organization** | Hrisian Petkov |
| **Network** | 87.121.52.0/24 (VPSBG) |
| **Risk Score** | 59/100 |
| **Threat Category** | Tor Exit Node |
| **DNSBL Listings** | 2 of 8 lists |
## Observed Services & Infrastructure
- Open Ports: 80/TCP (HTTP), 443/TCP (HTTPS), 22/TCP (SSH)
- TLS Certificate: CN=www.oj7cgbt5.net (subject), issuer CN=www.uaqcyo3s7qprr.com
- Network Role: Web Server / Tor Exit Node
- Geolocation: Sofia region (42.73°N, 25.49°E), RTT 130-134ms from probe origin
## Threat Intelligence Observations
- Tor Exit Node: Confirmed Tor exit node indicator present
- Blacklist Status: Listed on 2 DNSBLs out of 8 monitored lists
- Recent Activity: 68 total observations recorded
- Abuse Signals: Elevated severity listings observed in recent timeframe (medium to high)
- Operator Score: 0.2609 (Basic classification)
## Neighborhood Context
The /24 subnet (87.121.52.0/24) shows:
- Abuse Density: 0
- Classification: mostly_clean
- Active siblings: 1
- Threat siblings: 1
## Recommended Actions
Access Control:
- Implement enhanced verification for anonymous traffic from this IP
- Consider blocking or rate-limiting Tor exit node traffic
Monitoring:
- Increase logging verbosity for traffic from this IP address
- Review recent connection activity and request patterns
Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 87.121.52.101 -j DROP
# nftables
nft add rule inet filter input ip saddr 87.121.52.101 drop
# Nginx
deny 87.121.52.101;
# Cloudflare WAF
{"description": "Block 87.121.52.101 — IPDebrief risk score 59", "action": "block", "filter": {"expression": "ip.src eq 87.121.52.101"}}
# AWS WAF
{"Addresses": ["87.121.52.101/32"], "Description": "IPDebrief risk 59"}
```
## Assessment
This IP should be treated as a moderate-risk source requiring monitoring rather than immediate blocking. The Tor exit node classification indicates potential abuse for anonymized malicious traffic. However, the IP is not flagged as a known attacker or confirmed spam source. Implement firewall rules with appropriate logging to enable correlation of suspicious activity patterns.
---
*Report generated by IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Hrisian Petkov |
| ASN | AS34224 |
| Network Name | VPSBG |
| CIDR Block | 87.121.52.0/24 |
| RIR | RIPE |
| Country | BG |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 0% (None) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Tier 3 — Basic operator with some routing infrastructure |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 443 | https | tcp | — |
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
CN=www.in7f4p2udrcq3agcr5lp.net was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.| SANs | None |
| Valid From | 2026-03-03T00:00:00+00:00 |
| Valid Until | 2026-09-29T00:00:00+00:00 (expired) |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 210 days |
🛡️ Public Network Snapshot
| Origin ASN | AS34224 |
| Network Prefix | 87.121.52.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 60% | 2 | 28 |
| routing | 34% | 2 | 3 |
| services | 35% | 2 | 3 |
| ownership | 40% | 3 | 5 |
| reputation | 26% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 38% | 12 | 45 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-08 17:08:32 UTC |
| Last Seen | 2026-08-30 07:11:49 UTC |
| Profile Built | 2026-09-04 21:59:18 UTC |
| Data Freshness | Live |
| Signal Types | 27 |
| Total Observations | 111 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 87.121.52.101
Who owns the IP address 87.121.52.101?
87.121.52.101 is registered to Hrisian Petkov. The address falls within the 87.121.52.0/24 network block. Registration is held at RIPE.
Where is 87.121.52.101 located?
Geolocation data places 87.121.52.101 in Sofia. The local time zone is Europe/Sofia. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 87.121.52.101 malicious or safe?
87.121.52.101 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 87.121.52.101?
Responsive ports observed on 87.121.52.101 include 80, 443, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.
Is 87.121.52.101 a VPN, proxy, or data center address?
87.121.52.101 is classified as the Tor network based on network ownership and behavioural analysis.