Is 171.25.193.25 Safe? IP Analysis Report

Suspicious Fixed Line ISP
Sweden SE · Stockholm, Stockholm County · Foreningen digitala fri- och rattigheter
Known Threat High Abuse Score PTR Found
0 Risk Score

Suspicious

Abuse Score 100% AbuseIPDB
Reports 193 total
Reporters 0 users
Threat Feeds 1 matched
Domains 0 associated
Share: Twitter Facebook LinkedIn
JSON CSV
Is this IP safe?
Key Findings
Overall Verdict
This IP address shows suspicious signals.
AbuseIPDB: 100% abuse confidence
193 reports from 0 users
Threat Intelligence
Known threat — 1 feed
Analysis Sources
AbuseIPDB Flagged
Confidence score: 100%
Threat Feeds Detected
1 matches
Geolocation Found
Sweden · Stockholm
Reverse DNS Found
tor-exit-read-me.dfri.se
Summary
Verdict: Suspicious
Sweden (Stockholm)
Foreningen digitala fri- och rattigheter
AbuseIPDB: 100%
Known threat (1 feeds)
Analyze Another IP
Geolocation Information
Country Sweden SE
City Stockholm, Stockholm County
ISP Foreningen digitala fri- och rattigheter
Organization DFRI
ASN AS198093 Foreningen for digitala fri- och rattigheter
Network Details
ISP

Foreningen digitala fri- och rattigheter

Organization

DFRI

ASN

AS198093 Foreningen for digitala fri- och rattigheter

AbuseIPDB Report
100%
Abuse Score
193
Reports
0
Reporters
Fixed Line ISP
Assessment
Bad Reputation
This IP has been widely reported for abuse.
Threat Intelligence 1 feed
Reverse DNS (PTR)
tor-exit-read-me.dfri.se

What is 171.25.193.25?

171.25.193.25 is an IP address that was analyzed by ScamSandbox. Based on our automated analysis, this IP address exhibits suspicious characteristics commonly associated with malicious activity.

The IP address 171.25.193.25 is located in Stockholm, Sweden and is operated by Foreningen digitala fri- och rattigheter (AS198093 Foreningen for digitala fri- och rattigheter). The associated organization is DFRI.

The reverse DNS (PTR) lookup for this IP address resolves to tor-exit-read-me.dfri.se, which provides additional context about the infrastructure this IP belongs to.

According to the AbuseIPDB database, this IP address has an abuse confidence score of 100% with 193 abuse reports. A confidence score above 50% indicates that this IP has been significantly reported for abusive activities, including spam, port scanning, brute force attacks, or other malicious behavior.

This IP address has been identified as a known threat in our threat intelligence databases. It appears in 1 threat intelligence feed. The identified threat categories include: TOR Exit Nodes .

The overall risk score assigned to 171.25.193.25 by ScamSandbox is 40/100 (where 100 is the highest risk). This score is calculated by weighing signals from AbuseIPDB, threat intelligence feeds, geolocation data, reverse DNS, and community reports.

Security Provider Verdicts for 171.25.193.25

The table below shows the verdict from each security source checked during this analysis. A Flagged result means the source detected malicious or abusive activity. Clean means no threat was detected.

AbuseIPDB IP address abuse reports database
Flagged (100%)
Threat Intelligence Multi-source intelligence feeds (TOR, botnets, malware)
Threat Detected (1 feed)
TOR Exit Node TOR anonymization network check
TOR Node Confirmed
Reverse DNS PTR record and associated hostname
tor-exit-read-me.dfri.se
ScamSandbox Overall Assessment
Suspicious (40/100)

What to do about 171.25.193.25?

If you have observed traffic from this IP address or it has attempted to connect to your systems, here are the recommended actions:

  1. Do not interact with this IP address — do not respond to suspicious requests or click on associated links.
  2. Block the IP in your firewall — add 171.25.193.25 to your blocklist (iptables, UFW, Windows Firewall, or your network firewall).
  3. Report the IP — submit a report on AbuseIPDB to help the community.
  4. Check your logs — review your server/firewall logs to identify any suspicious activity from this IP.
  5. Contact the hosting provider — if malicious activity persists, contact the ISP or hosting provider (Foreningen digitala fri- och rattigheter) to report the abuse.

Frequently Asked Questions about 171.25.193.25

Based on our analysis, 171.25.193.25 is not considered safe. The IP address has been flagged as suspicious with a risk score of 40/100 and is identified as a known threat in our intelligence feeds. We recommend blocking this IP.

The IP address 171.25.193.25 is managed by Foreningen digitala fri- och rattigheter (organization: DFRI) , with autonomous system number AS198093 Foreningen for digitala fri- och rattigheter. It is located in Stockholm, Sweden. The ISP is responsible for the IP address block that includes 171.25.193.25, but the end user controlling the server may be a customer of this ISP.

Yes, 171.25.193.25 is identified as a TOR exit node. TOR exit nodes are the final relays in the TOR network — traffic passing through TOR appears to originate from the exit node's IP address. This means malicious traffic observed from this IP could come from any TOR user worldwide, not necessarily from the node operator. However, TOR exit nodes are often used for anonymization activities that may include scanning, brute force, or spam. It is recommended to block TOR exit nodes if your service does not need to be accessible via TOR.

Yes, 171.25.193.25 is a known threat. This IP address appears in 1 threat intelligence feed. The identified threat categories include: TOR Exit Nodes. This means this IP has been associated with malicious activities such as port scanning, brute force attacks, malware distribution, botnet exploitation, or denial of service attacks. It is strongly recommended to block this IP address and report any suspicious activity.

Community Reports

No community reports yet for 171.25.193.25. Be the first to share your experience.