IPDebrief

96.27.198.133

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

## IP Intelligence Briefing: 96.27.198.133/32

Classification: Low Risk (Score: 25/100)

Date of Analysis: Current

Jurisdiction: United States (Newark, NJ)

Executive Summary

Target IP 96.27.198.133 is classified as a Tor Exit Node with low-risk characteristics. The address is hosted on WideOpenWest infrastructure (ASN 12083) and is listed on 1 of 8 DNS blacklists with basic operator scoring. No active services or open ports were detected during scanning. The surrounding /24 subnet shows clean classification with zero abuse density, indicating this IP is not part of a broader malicious cluster.

Risk Assessment

Technical Profile

Geolocation:

DNS Resolution:

Network Services:

Threat Indicators

Observation History

Sixteen signal observations recorded. Most recent activity observed 2026-07-21. Consistent Tor exit node classification across observation windows. No escalation in threat severity noted.

Neighborhood Analysis

Subnet 96.27.198.0/24 classification: Clean

No neighboring IPs identified as malicious.

Related Entities

Recommended Actions

No immediate action required based on current risk profile. However, the following considerations apply:

1. Traffic Monitoring: Monitor for Tor traffic patterns and potential abuse of exit node functionality

2. DNSBL Review: Investigate the specific blacklist listing to determine if false positive or legitimate abuse

3. Baseline Establishment: Establish traffic baseline for legitimate Tor usage vs. malicious activity

4. Periodic Review: Re-evaluate classification during scheduled threat intelligence cycles

Intelligence Conclusion

This IP represents a Tor exit node with minimal threat characteristics. While Tor exit nodes can be leveraged for malicious activity, the low-risk score, clean neighborhood, and absence of active services suggest limited immediate threat. Recommend monitoring rather than blocking to avoid legitimate user impact, while maintaining awareness of potential abuse vectors.

Analyst Notes: WideOpenWest is a residential ISP provider. Tor exit nodes on residential infrastructure may indicate legitimate privacy usage or abuse. Context-dependent policy application advised.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇺🇸 United States
RegionMichigan
CityUtica
Timezone—
Latitude42.64
Longitude-83.05

🏢 Ownership & Registration

OrganizationWide Open West
ASNAS12083
Network NameMI-DIMO
CIDR Block96.27.198.0/24
RIRARIN
CountryUnited States
Abuse Contact—

🌐 DNS Intelligence

PTRd27-96-133-198.evv.wideopenwest.com
Forward ConfirmedYes — FCrDNS verified
Forward Hostnamesd27-96-133-198.evv.wideopenwest.com

🔐 DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown — Insufficient routing data to classify
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Server—
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS12083
Network Prefix96.27.198.0/24
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
28%
25
routing
8%
11
services
28%
23
ownership
12%
22
reputation
14%
13
geolocation
12%
22
Overall17%1016
Coverage: 6/6 dimensions · Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

📅 Observation Timeline 🔄 Live

First Seen2026-07-08 22:16:05 UTC
Last Seen2026-08-26 22:14:32 UTC
Profile Built2026-08-29 07:19:49 UTC
Data FreshnessLive
Signal Types22
Total Observations25
🔍 22 signal types · 25 observations collected
This report is generated from 22+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 96.27.198.133

Who owns the IP address 96.27.198.133?

96.27.198.133 is registered to Wide Open West. The address falls within the 96.27.198.0/24 network block. Registration is held at ARIN.

Where is 96.27.198.133 located?

Geolocation data places 96.27.198.133 in Utica, Michigan, United States. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 96.27.198.133 malicious or safe?

96.27.198.133 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.

What is the hostname for 96.27.198.133?

The reverse DNS (PTR) record for 96.27.198.133 is d27-96-133-198.evv.wideopenwest.com. This hostname is forward-confirmed, meaning it resolves back to the same address.

🏘️ Related IP Addresses

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.