Tor exit node: traffic belongs to many anonymous users.
- Tor exit
- true
| Source | Finding | Confidence | Age | Signal |
|---|---|---|---|---|
| 100% abuse confidence from 204 reporters, newest today; web app attack, hacking, brute-force. | 100% | 0 days recent | Strong | |
| 15/91 vendors (16.5%) flag it: moderate multi-vendor detection, well short of a majority. | 15/91 | 0 days recent | Moderate | |
| Observed scanning the internet, classified malicious, today. | — | 0 days recent | Suspicious | |
| IOCSCAPE knowledge base | Tor exit node: traffic belongs to many anonymous users. | — | — | Context |
| Network TOR-EXIT (185.220.100.240 - 185.220.100.255), DE; F3NETZE, F3Netze NOC, F3 Netze e.V.. | — | — | Context | |
| Announced in 185.220.100.0/24 by AS205100 (F3NETZE F3 Netze e.V.). | — | — | Context | |
| Open ports 22, 80, 9001, 9200, 10050. | — | — | Context | |
| Listed as an active Tor exit node. | — | 1 day recent | Context | |
| Referenced in 50 community pulses, which are unverified. | — | — | Neutral |
Coverage · checked, no record: ThreatFox, URLhaus, Feodo Tracker, Emerging Threats, DShield · failed: none
Malicious: a listed Tor exit node, treated as a malicious traffic source by policy. 100% abuse confidence from 204 reporters, newest today; web app attack, hacking, brute-force. Reported abuse adds to that. The traffic is from anonymous Tor users, not the relay operator.
Traffic from a Tor exit belongs to anonymous Tor users; it does not implicate the relay operator.
| Source | Finding | Confidence | Age | Signal |
|---|---|---|---|---|
| 100% abuse confidence from 204 reporters, newest today; web app attack, hacking, brute-force. | 100% | 0 days recent | Strong | |
| 15/91 vendors (16.5%) flag it: moderate multi-vendor detection, well short of a majority. | 15/91 | 0 days recent | Moderate | |
| Observed scanning the internet, classified malicious, today. | — | 0 days recent | Suspicious | |
| IOCSCAPE knowledge base | Tor exit node: traffic belongs to many anonymous users. | — | — | Context |
| Network TOR-EXIT (185.220.100.240 - 185.220.100.255), DE; F3NETZE, F3Netze NOC, F3 Netze e.V.. | — | — | Context | |
| Announced in 185.220.100.0/24 by AS205100 (F3NETZE F3 Netze e.V.). | — | — | Context | |
| Open ports 22, 80, 9001, 9200, 10050. | — | — | Context | |
| Listed as an active Tor exit node. | — | 1 day recent | Context | |
| Referenced in 50 community pulses, which are unverified. | — | — | Neutral | |
| No record. | — | — | No record | |
| No record. | — | — | No record | |
| No record. | — | — | No record | |
| No record. | — | — | No record | |
| DShield | Not among the 1,000 IPs most reported by DShield sensors today. | — | — | No record |
Malicious: a listed Tor exit node, treated as a malicious traffic source by policy. 100% abuse confidence from 204 reporters, newest today; web app attack, hacking, brute-force. Reported abuse adds to that. The traffic is from anonymous Tor users, not the relay operator.
Tor exit node: traffic belongs to many anonymous users.
Network TOR-EXIT (185.220.100.240 - 185.220.100.255), DE; F3NETZE, F3Netze NOC, F3 Netze e.V..
Traffic from a Tor exit belongs to anonymous Tor users; it does not implicate the relay operator.
Relationship ≠ ownership. Shared IPs, ASNs or platforms never imply the same operator.
No group is directly linked to this indicator by any source.
Reported targets: Finance, Defense, Industrial, Government, technology, financial-services, United States of America, Turkey, Ukraine, Romania, Czechia, United Kingdom of Great Britain and Northern Ireland, Norway, Lithuania, Estonia, Latvia
Opens the indicator in the source's own site (new tab).
No group is directly linked to this indicator by any source.
Reported targets: Finance, Defense, Industrial, Government, technology, financial-services, United States of America, Turkey, Ukraine, Romania, Czechia, United Kingdom of Great Britain and Northern Ireland, Norway, Lithuania, Estonia, Latvia
Traffic from a Tor exit belongs to anonymous Tor users; it does not implicate the relay operator.
Announced in 185.220.100.0/24 by AS205100 (F3NETZE F3 Netze e.V.).
Observed scanning the internet, classified malicious, today.
Open ports 22, 80, 9001, 9200, 10050.
Listed as an active Tor exit node.