Threat LevelHIGH58/1001 rule type
8 incidents on record ยท confirmed on global blocklist ยท persistent 9-day campaign ยท last seen 2d ago
| PTR | lain.45.137.201.100.aluy.net |
| Org / ASN | Julian Achter |
| Country | ๐ฎ๐น Italy |
| City | Milan, Lombardy |
| Timezone | Europe/Rome |
Attack Analysis
IDS: Tor Exit Node
This IP is a known Tor network exit node. Tor anonymizes user traffic by routing it through a series of relays; exit nodes are the final hop where traffic re-enters the public internet. While Tor has legitimate privacy uses, it is heavily abused for anonymous attacks, credential stuffing, and fraud โ as the real attacker IP is concealed behind the exit node.
Reports (8)
| Date | Severity | Description |
|---|---|---|
| 17 Jun 2026 - 14:33 | high | IDS: Tor exit node โ known anonymization network โ ET TOR Known Tor Exit Node Traffic group 102 |
| 17 Jun 2026 - 14:33 | high | IDS: Tor exit node โ known anonymization network โ ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 102 |
| 14 Jun 2026 - 01:13 | high | IDS: Tor exit node โ known anonymization network โ ET TOR Known Tor Exit Node Traffic group 102 |
| 14 Jun 2026 - 01:13 | high | IDS: Tor exit node โ known anonymization network โ ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 102 |
| 10 Jun 2026 - 14:57 | high | IDS: Tor exit node โ known anonymization network โ ET TOR Known Tor Exit Node Traffic group 102 |
| 10 Jun 2026 - 14:57 | high | IDS: Tor exit node โ known anonymization network โ ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 102 |
| 8 Jun 2026 - 16:00 | high | IDS: Tor exit node โ known anonymization network โ ET TOR Known Tor Exit Node Traffic group 102 |
| 8 Jun 2026 - 16:00 | high | IDS: Tor exit node โ known anonymization network โ ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 102 |
EagleEye Intelligence