IP Lookup: Geolocate and Analyze Any IP Address
IP lookup online with technical context, reputation and risk scoring
An IP lookup in seconds with more than 20 correlated sources: cross-checked reputation (AbuseIPDB, VirusTotal, GreyNoise, AlienVault OTX), BGP/RPKI validation, CVEs detected via Shodan, domain co-hosting, cloud attribution (AWS, GCP, Azure, Cloudflare), aggregated threat-intel (IPsum, CINS, Feodo, Spamhaus DROP), passive DNS and blacklists. The rigorous way to check an IP, look up a suspicious IP and check an IP’s reputation before acting on it — with 4D risk scoring, an actionable executive summary (suggested decision, risk level and immediate action), a two-part AI report (one in plain language, one technical), deterministic forensic hypotheses, and a signed PDF with chain of custody.
8.8.8.8 or 2001:4860:4860::8888 · Ideal for threat intel, log analysis, fraud and origin checksSee a full sample report Click to expand a real screenshot of an IP analysis — the image is only a partial view of the report; below it you’ll find the full list of everything you get
The full IP report includes more than 60 correlated data points grouped into 4 major layers. The image below is a partial view: for the full picture, see the list below.
🎯 Quick decision (top section)
- Weighted 4D scoring: Final risk + Technical (20%) + Reputation (40%) + Geographic (15%) + Exposure (25%) with consistent LOW / MEDIUM / HIGH / CRITICAL levels
- Factors behind the score: pills for each concrete driver (hosting_provider, abuseipdb_high_confidence, vt_high_detection, geolocation_inconsistency, scanner, etc.)
- Actionable executive summary in 3 lines: Suggested decision · Risk level · Immediate action
🧠 Two-part AI report (OpenAI gpt-5.4)
- PART 1 — for non-technical readers: intro paragraph + 4 pre-built bullets (OPERATOR · CONNECTION TYPE · PUBLIC REPUTATION · INTERNET PRESENCE) + human verdict + What to do with this address
- PART 2 — technical: Operator attribution, infrastructure posture, public exposure and software, reputation and history (table), co-hosting and DNS history, cross-references between sources, anomalies and limitations, final risk
- More than 20 control rules + PART 1 bullets that the AI copies verbatim from the backend (zero invention)
📊 Detailed data cards
- Contribution by source: vendor weights applied to reputation risk (AbuseIPDB · VT · GreyNoise · OTX in %)
- Local intelligence: 6 scannable mini-cards with ✓/!/— icons (Reverse DNS, Blacklists, Tor, GreyNoise, AlienVault, Ports)
- AbuseIPDB: confidence %, reports, distinct users, last report, usage type, ISP, domain, hostnames, official whitelist
- VirusTotal: malicious/suspicious/harmless/undetected + detection %, reputation, community votes, AS owner, network
- IPinfo / Geolocation: country, region, city, postal code, coordinates, timezone, ASN, ISP, hostname, anycast
- IP type: category, ISP type, ASN fingerprint with confidence, operator, nature (corporate/hosting/residential/Tor)
⚔ Arsenal v2 (11 deep technical cards)
- Cloud attribution: provider, region, service, CIDR (AWS / GCP / Azure / Cloudflare)
- BGP/RPKI + RIR validation: valid/invalid/unknown status, published ROAs with prefix→AS+max_length, BGP hijack alert if invalid_asn, RDAP entities, legacy WHOIS for the block
- Shodan InternetDB technical exposure: vulnerabilities, exposed ports, organization, country, last scan
- AlienVault OTX pulses: total count + top 3-5 pulses with name, date, description and tags
- Correlated threat intelligence: IPsum (30+ blacklists), CINS Army, Feodo Tracker (C2 botnets), Spamhaus DROP/EDROP, DShield SANS
- DShield SANS history: threat feeds with first/last observation (cryptominer, openresolver, SSH/RDP brute-force, scanner, web attacker, botnet C2)
- Domain co-hosting: count, rating (unique / low / medium / massive shared hosting), sample of neighbors
- Passive DNS history (Mnemonic): records seen, first/last observation, associated historical queries
- ASN reputation (CIRCL BGP Ranking): historical maliciousness rank of the ASN
- Tor relay metadata (Onionoo): nickname, country, observed bandwidth, version, first seen (only if the IP is a Tor node)
- Authoritative abuse contact: emails triangulated across 3 sources (RIPEstat + DShield + WHOIS), authoritative RIR
🔬 Deterministic anomalies and recommendations (forensic, no AI)
- Cross-source anomalies detected: contradictions between sources (IPinfo vs. VirusTotal geolocation, mixed valid+invalid RPKI ROAs, Tor vs. negative reverse DNS flag, degraded DNSBL blacklists, AbuseIPDB whitelist with historical reports, etc.)
- Specific actionable recommendations: who to report abuse to (concrete emails), which blacklists to check, which domains to cross-reference in the domain tool, which pivots to try based on the IP’s profile
- Forensically citable evidence — generated in code from correlated sources, with zero possibility of hallucination
📋 Traceability and deliverables
- Verifiable public sources: list of the 14+ sources consulted with a ✓ status and a link to reproduce the lookup manually
- Follow-up questions: up to 3 questions to the AI analyst about the report results (gpt-5.4-mini)
- RFC 3161-signed PDF: cover page with premium scoring + risk bar with factors · full AI report on a dedicated page · technical data · anomalies · FreeTSA timestamp · SHA-256 hash · public verification URL · corporate signature block + INCIBE Emprende seal
- Suitable as evidence: electronic evidence in court, documentary annex for due diligence, support for an expert report, regulatory evidence for KYC/AML compliance, journalistic annex

What is this online IP lookup tool?
IntelMind’s online IP lookup is the fast, rigorous way to check a suspicious IP from an OSINT cyber intelligence and security angle. It’s not a simple IP WHOIS: it’s a correlation engine that cross-checks more than 20 sources in under 5 seconds to return an actionable executive verdict.
This tool doesn’t just tell you whether an IP is «public»: it correlates technical risk signals (RPKI, Shodan ports/CVEs, CPE software), cross-checked reputation (AbuseIPDB, VirusTotal, GreyNoise, IPsum, CINS, Feodo, Spamhaus DROP), cloud attribution (AWS, GCP, Azure, Cloudflare), domain co-hosting, historical passive DNS and geolocation to produce a clear, useful, exportable verdict. In short, a single lookup replaces checking an IP across five different vendors.
IP reputation, geolocation, ASN and scoring in this IP lookup
- IP reputation: AbuseIPDB, VirusTotal, GreyNoise, AlienVault OTX, IPsum (30+ aggregated blacklists), CINS Army, Feodo Tracker and Spamhaus DROP/EDROP in real time.
- BGP/RPKI infrastructure: ASN/ISP, exact BGP prefix, RPKI validation (valid/invalid/unknown), ASN-fingerprinted network type (hosting/datacenter, ISP, CDN, cloud), reverse DNS and ports. Go to the domain tool
- Cloud attribution: automatic detection of whether the IP belongs to AWS, GCP, Azure or Cloudflare, with region and service.
- Anonymization and network type: Tor exit detection (official list) + ASN-fingerprint classification (hosting/datacenter, residential ISP, CDN, cloud) + DNS blacklists with «degraded lookup» transparency.
- 4D scoring for this IP lookup: technical (20%), reputation (40%), context (15%), exposure (25%).
- Co-hosting and history: domains hosted on the IP (HackerTarget reverse-IP) and historical passive DNS (Mnemonic).
- Explanatory professional summary: results interpreted without losing technical precision.
- Follow-up questions: dig deeper into specific findings from the report (up to 3 questions per lookup).
- Signed PDF export: a report ready to share, document or archive forensic findings.
- Centralized workflow: less time jumping between tools, more focus on the OSINT analysis. Learn about the platform
Quick FAQ
Does it detect if an IP is a Tor exit node?
Yes. The tool checks the address against the public list of Tor exit nodes and flags full anonymity when present.
How many credits does it cost, and what’s included?
8 credits per lookup. The IP analysis correlates more than 20 sources in parallel: AbuseIPDB, VirusTotal, GreyNoise, AlienVault OTX, Shodan InternetDB (CVEs and CPEs), IPinfo, DNS blacklists, Tor, RIPEstat (BGP/RPKI/abuse-contact), HackerTarget (co-hosting), Mnemonic Passive DNS, DShield SANS, CIRCL BGP Ranking, IPsum (aggregates 30+ lists), CINS Army, Feodo Tracker, Spamhaus DROP/EDROP, AWS/GCP/Azure/Cloudflare ranges, port scan, rdap.org, GeoIP and ASN fingerprinting. It includes 4D scoring (technical, reputation, context, exposure), an executive verdict, deterministic anomalies and recommendations (no AI, zero hallucinations) and a two-part professional summary with a 3-line actionable executive summary (decision / level / action) plus a plain-language analysis for non-technical readers and a detailed technical analysis. On the Profesional Plan (€79/month with 250 credits), that’s ~31 monthly lookups at a substantially lower cost than combining Spur+IPQS+AbuseIPDB.
What does the IP analysis PDF include?
A highlighted actionable executive summary (suggested decision, risk level, immediate action), a two-part AI report with a plain-language analysis for non-technical readers and a detailed technical analysis, 4D risk scoring (technical, reputation, context, exposure), local intelligence (blacklists, Tor exit nodes, GreyNoise), Shodan InternetDB (detected ports, CPE and CVEs), BGP/RPKI validation with the exact prefix, cloud attribution (AWS/GCP/Azure/Cloudflare), domain co-hosting, historical passive DNS, deterministic anomalies and recommendations (no AI), and correlated vendor and aggregated threat-intel data (AbuseIPDB, VirusTotal, AlienVault OTX, IPsum, CINS, Feodo, Spamhaus DROP). PDF signed with chain of custody: SHA-256 hash, RFC 3161 timestamp and a public verification URL.
Reputation, blacklists and IP triage
How can I tell if an IP address is malicious or blacklisted?
IntelMind simultaneously checks AbuseIPDB, VirusTotal (90+ antivirus engines), GreyNoise, AlienVault OTX and aggregated threat-intel (IPsum 30+ blacklists, CINS Army, Feodo Tracker, Spamhaus DROP/EDROP). If the IP appears in one or more sources with recent reports, the risk score rises and the executive verdict flags it as a malicious IP with a recommended action. A single detection with no cross-confirmation is treated as a low-confidence signal to avoid false positives. DNS blacklist lookups (Spamhaus, SORBS, Barracuda, SpamCop) are complementary and marked as a «degraded lookup» when the list doesn’t authorize public use.
What’s the difference between geolocating an IP and running an OSINT IP analysis?
Geolocation only places the IP in an approximate country, city or coordinate. OSINT IP analysis goes much further: it includes cross-checked reputation across AbuseIPDB, VirusTotal, GreyNoise and AlienVault OTX, Tor exit detection + ASN-based network type classification, historical malicious activity, open ports and CVEs detected by Shodan InternetDB, BGP/RPKI validation, domain co-hosting and a multidimensional risk score with an executive verdict. IntelMind combines every layer in a single lookup.
Identification: ASN, WHOIS and anonymity detection
What are ASN and WHOIS analysis used for on an IP?
The ASN (Autonomous System Number) identifies the network and operator that controls the IP block the analyzed address belongs to. Combined with WHOIS and RDAP (with the exact BGP prefix, allocation date and authoritative registrant), it reveals whether the IP belongs to a cloud/datacenter provider (a signal of shared hosting or a server), a residential ISP, a corporate network or a CDN. This is key to contextualizing the IP’s real risk and getting the authoritative abuse contact to report it.
Can it detect if an IP is Tor or hosting/datacenter type?
Yes. IntelMind checks the address against the official list of Tor exit nodes and classifies the network type via ASN fingerprinting (categories: hosting/datacenter, residential ISP, CDN, cloud infrastructure or unknown). When the IP is Tor or shared hosting, the score reflects it in the context and exposure dimensions. Detecting commercial VPNs by ASN is a gray area (providers rotate ranges constantly), so IntelMind never claims «this is a VPN» unless the IP sits on known hosting infrastructure.
4D scoring and the block/allow decision
What does the 4D risk score mean in an IP analysis?
The 4D score evaluates the IP across four weighted dimensions: Technical (RPKI, BGP prefix, Shodan ports/CVEs, CPE — 20%), correlated Reputation (AbuseIPDB, GreyNoise, VirusTotal, IPsum, CINS, Feodo, Spamhaus DROP — 40%), Context (geolocation, Tor exit, ASN-based network type — 15%) and Exposure (exploitable CVEs, domain co-hosting, known scanners — 25%). The final score runs 0 to 100: LOW (0-30) indicates a clean IP; MEDIUM (30-60) calls for verification; HIGH (60-100) justifies a block or further investigation.
How can I tell if an IP is malicious before blocking it?
IntelMind checks the address against AbuseIPDB, VirusTotal, Spamhaus and several DNS blacklists to check an IP’s reputation in real time. The report also lets you look up an IP from another angle: ASN, network type, open ports detected by Shodan and approximate geolocation, so the verdict never depends on a single source.
Arsenal v2: CVEs and BGP/RPKI validation
What is a CVE, and how does IntelMind detect vulnerabilities on an IP?
A CVE (Common Vulnerabilities and Exposures) is a standard identifier for a publicly documented software vulnerability. During an IP analysis, IntelMind queries Shodan InternetDB to get the open ports, detected products (CPE) and the list of known CVEs tied to those services. If the IP exposes outdated software with a critical CVE, the exposure dimension of the 4D score rises and the verdict recommends review or isolation. It’s a mini attack-surface audit without ever touching the target.
How is a BGP route validated with RPKI, and why does it matter for an IP lookup?
RPKI (Resource Public Key Infrastructure) is the system that cryptographically signs the allocation of BGP prefixes to their legitimate operators. IntelMind queries RIPEstat and shows whether the IP’s route origin is valid (legitimate and signed), invalid (possible route hijack) or unknown (no published ROA). An IP marked invalid is a serious signal: someone is announcing that prefix without authorization — a technique used in BGP hijacking. This is information a traditional IP WHOIS never provides.
Arsenal v2: co-hosting, cloud attribution and aggregated threat-intel
What is domain co-hosting (shared hosting) in an IP analysis?
Domain co-hosting shows how many DNS names resolve to the same IP address. IntelMind queries HackerTarget reverse-IP and shows the list. An IP with a single domain suggests dedicated infrastructure; hundreds or thousands of domains indicate massive shared hosting (typical of cheap hosters or phishing farms). This signal is key in antifraud investigations and subdomain takeovers: if an IP hosts both your brand and malicious domains, the risk spills over into your own environment.
How does IntelMind detect if an IP belongs to AWS, GCP, Azure or Cloudflare?
IntelMind maintains a local database of the official ranges published by AWS, Google Cloud, Microsoft Azure and Cloudflare, refreshed daily by a dedicated timer. When an IP is looked up, the engine does CIDR matching with ipaddr.js and returns the provider, service (for example AMAZON, EC2, S3) and region (us-east-1, eu-west-1…). This cloud attribution dramatically changes the read: a clean residential IP and a cloud datacenter IP have completely different antifraud profiles.
How does IntelMind correlate 30+ blacklists into a single threat-intel verdict?
Correlated threat-intel is the practice of aggregating multiple independent sources to increase confidence in a risk signal. IntelMind combines IPsum (which already merges 30+ public blacklists with a 1-10 score), CINS Army (malicious IPs verified by Sentinel IPS), Feodo Tracker (banking botnet C2) and Spamhaus DROP/EDROP (hijacked or mass-spam ranges). If an IP appears on several independent lists, the verdict raises the reputation dimension of the 4D score; if it appears on just one, it’s treated as low-confidence noise to avoid false positives.
What format does the AI report take for an IP analysis?
The AI report combines three layers built for B2B decisions: (1) a highlighted 3-line actionable executive summary at the top with a suggested decision, risk level and immediate action, scannable in 5 seconds; (2) a non-technical part that translates what the IP is, who runs it and how it’s used into plain language; and (3) a technical part covering operator attribution, infrastructure posture (RPKI, ROAs, abuse contacts), public exposure with CVEs, correlated reputation in a table, co-hosting and historical passive DNS, cross-references between sources, and detected anomalies. The AI model (OpenAI gpt-5.4) works on forensic findings pre-computed in code (zero hallucinations) and applies more than 20 IP-specific control rules.
What are the report’s deterministic anomalies and recommendations?
This is a dedicated section the engine generates without AI, built entirely from the backend’s correlated sources, so it can’t invent or hallucinate anything. It highlights two blocks of unique expert value: (1) cross-source contradictions detected — for example diverging IPinfo vs. VirusTotal geolocation, mixed valid+invalid RPKI ROAs (potential BGP hijack), degraded DNSBL blacklists (partial result), Tor vs. negative reverse DNS flag — and (2) specific actionable recommendations generated from the risk level and concrete drivers (who to report abuse to, which blacklist to check, which domains to cross-reference). The operator’s technical detail, exposure, digital footprint and posture are already shown above in the Arsenal v2 cards with badges and colors — this section avoids duplication and focuses on citable expert value.
The complete guide to online IP lookups with OSINT
In practice, an online OSINT IP lookup is a core piece of cybersecurity, forensic investigation and threat intelligence. IntelMind queries more than 20 correlated sources in parallel to deliver a complete technical x-ray of any IPv4 or IPv6 address: from geolocation and ASN to BGP/RPKI validation, CVEs detected by Shodan, domain co-hosting and aggregated threat-intel from IPsum, CINS, Feodo and Spamhaus DROP. That’s why this OSINT IP workflow is essential for SOC, antifraud and due diligence teams.
IntelMind’s IP lookup doesn’t stop at one layer: it links technical signals with cross-checked reputation and human context. It also lets an analyst find out who owns an IP, validate whether a BGP route is legitimate, detect whether the address is hosting suspicious domains, and export a signed PDF with digital chain of custody.
This capability also answers the most common operational questions in a single lookup: is this IP a datacenter proxy? Does it belong to a known cloud range? Are there exploitable CVEs exposed? What domains are co-hosted on this host? As a result, it works both to check an IP in real time and to reconstruct its passive history.
Geolocation and network context in an IP lookup
First, every IP address is assigned to a block managed by an ISP or hosting provider within an Autonomous System (ASN). IntelMind extracts the approximate geolocation (city, region, country), the ISP, the usage type (residential, datacenter, education) and the ASN with its name and organization. This lets you quickly tell whether an IP belongs to a home user, a cloud server, a university or corporate infrastructure. Automatic cloud attribution (AWS, GCP, Azure, Cloudflare) also saves time when you need to check a suspicious IP tied to fraud from shared infrastructure.
IP reputation and abuse scoring in an IP lookup
An IP’s reputation is assessed by cross-checking multiple threat databases. AbuseIPDB, for example, provides a confidence score based on community abuse reports. GreyNoise, meanwhile, distinguishes between benign traffic (research scanners) and genuine malicious activity. Cross-referencing both sources reduces false positives and helps decide whether an IP is a genuine threat or just internet noise. Since checking an IP’s reputation properly requires aggregating sources, IntelMind also adds IPsum (30+ combined lists), CINS Army, Feodo Tracker (botnet C2) and Spamhaus DROP/EDROP.
Threat Intelligence: VirusTotal and AlienVault OTX
VirusTotal aggregates results from more than 90 antivirus engines and sandboxes. Specifically, IntelMind checks the detections tied to the IP, the domains it resolves to, and scanned URLs. AlienVault OTX (Open Threat Exchange), meanwhile, provides indicators of compromise (IoCs), threat pulses and context on malicious campaigns where the IP has been observed.
Exposed infrastructure and CVEs in an IP lookup: Shodan
Shodan InternetDB continuously scans the internet and logs the open ports, exposed services, banners and software versions for every IP. From there, IntelMind extracts the ports, protocols, detected products (CPEs) and known exploitable CVEs on that infrastructure. A server with unnecessary open ports or outdated software is a significant operational risk indicator and raises the exposure dimension of the 4D score. This layer effectively turns the IP lookup into a mini attack-surface audit without ever touching the target.
DNS blacklists and block lists
DNS blacklists (DNSBLs) are real-time databases that track IPs tied to spam, malware, botnets or abusive activity. IntelMind also checks Spamhaus (SBL, XBL, PBL), SURBL, Barracuda, SpamCop and other lists. An IP present on multiple blacklists at once is a strong indicator of compromise or malicious use.
Arsenal v2 of the IP lookup: BGP/RPKI validation, co-hosting, cloud attribution, passive DNS and aggregated threat-intel
Arsenal v2 extends the IP lookup with five layers that very few tools combine in a single query. First, BGP/RPKI validation against RIPEstat shows whether the route origin is legitimate (valid), hijacked (invalid) or has no published ROA (unknown). Domain co-hosting (HackerTarget reverse-IP), meanwhile, reveals which names share that address — key for detecting massive shared hosting, subdomain takeovers and phishing patterns. Mnemonic’s passive DNS (TLP-WHITE) also reconstructs the IP’s historical resolution record, letting you find out who owns a suspicious IP beyond its current WHOIS.
As for cloud attribution, IntelMind automatically detects whether the IP belongs to AWS, GCP, Azure or Cloudflare, with a specific CIDR, region
and service (for example, us-east-1 on AMAZON, or an edge node on Cloudflare). A cloud datacenter IP therefore
changes the risk profile: likely a proxy or backend, not a residential user.
This level of attribution is what turns a plain IP WHOIS into an actionable verdict.
Finally, aggregated threat-intel combines IPsum (30+ blacklists with a 1-10 score), CINS Army, Feodo Tracker (botnet C2), Spamhaus DROP/EDROP, DShield SANS (honeypots) and CIRCL BGP Ranking (the ASN’s historical rank). The result is a verdict that no longer depends on a single vendor: if the IP appears across five independent sources, confidence in the signal is maximal; if it only appears on one, IntelMind treats it as low-confidence noise to avoid false positives when checking an IP in production.
Tor and network-type detection: how to identify anonymous traffic
IntelMind specifically identifies whether an IP is a Tor exit node (direct verification against the project’s official list) and classifies the network type via ASN fingerprinting: hosting/datacenter, residential ISP, CDN or cloud. This classification is critical in antifraud investigations: a residential IP has a very different risk profile from a datacenter IP that could be operating as a proxy. Detecting commercial VPNs by ASN is deliberately conservative — providers rotate ranges constantly, and a false positive does more damage than an honest «network type: hosting.»
4D scoring for an IP lookup: technical, reputation, context and exposure
This IntelMind scoring system evaluates every IP across four weighted dimensions:
- Technical (20%) — RPKI validation, BGP prefix, Shodan ports/CVEs, detected CPE software.
- Correlated reputation (40%) — AbuseIPDB, GreyNoise, VirusTotal, AlienVault OTX, IPsum, CINS, Feodo, Spamhaus DROP.
- Context (15%) — Tor exit, network type (hosting/datacenter/ISP/CDN), geolocation.
- Exposure (25%) — exploitable CVEs, domain co-hosting, known scanners, passive DNS.
The final score (0-100) translates into a classification: LOW (clean IP), MEDIUM (mixed signals) or HIGH (confirmed threat or active compromise). Ultimately, this 4D score is what turns an IP lookup into a documentable decision, not a hunch.
Professional use cases for IP lookups
Online IP lookups also have direct applications across professional fields that need to check an IP, look up an IP and check an IP’s reputation in seconds:
- SOC and Blue Team: alert triage, IoC verification, firewall log analysis and correlation with threat-intel feeds (MITRE ATT&CK).
- Antifraud: checking whether a transaction’s IP is residential or a proxy, datacenter or Tor, and its abuse history.
- OSINT investigation: putting IPs found in logs, emails, domains or security incidents into context.
- Infrastructure management: auditing the exposure of your own IPs on Shodan and blacklists.
- Due diligence: checking the reputation of vendors’, partners’ or third-party infrastructure IPs.
Geolocating an IP: real accuracy and the limits of GeoIP
Geolocating an IP with OSINT is one of the most requested lookups, because almost everyone needs to answer the same question: where is this user connecting from? It’s worth understanding GeoIP’s real reach before basing a decision on it. Public databases (MaxMind GeoLite, IP2Location, ipinfo) get the country right 95-99% of the time, but the specific city is only reliable around 60-75% of the time, and neighborhood-level accuracy is marketing — an IP can’t be mapped to a specific street.
IntelMind shows the estimated country, region and city with the honesty of flagging it as an approximation, alongside the ASN, ISP and network type. For an antifraud analysis or a SOC triage, that granularity is enough; an investigation that needs an exact geographic location requires a court order to the carrier. Cloud attribution and co-hosting add the context that GeoIP alone can’t provide.
Looking up, checking and reputation-checking an IP: the typical workflow
When someone wants to look up an IP, check an IP or check an IP’s reputation, the OSINT workflow IntelMind applies is always the same: first it confirms the IP is routable (not loopback, private or reserved), then it extracts geolocation + ASN + BGP prefix + RPKI validation, in parallel it queries AbuseIPDB (public reports), VirusTotal (links to malware or C2), AlienVault OTX (presence in threat-intel feeds), DShield SANS, IPsum/CINS/Feodo/Spamhaus DROP (aggregated threat-intel) and DNS blacklists (Spamhaus, Barracuda, SORBS). It then cross-checks Shodan InternetDB for open ports, software (CPE) and exploitable CVEs, runs cloud attribution (AWS/GCP/Azure/Cloudflare), reverse-IP for co-hosting, and Mnemonic passive DNS. All in parallel, in under 5 seconds. Finally, the professional summary translates the result into an actionable decision: trustworthy, caution, block. In short, anyone who legitimately needs to trace an IP gets the condensed OSINT workflow right here.
Is this IP Tor? Detecting Tor exits and network type via ASN
One of the most common antifraud questions is «where is this IP coming from?». IntelMind provides two objective, verifiable signals: (1) Tor exit node — direct verification against the Tor project’s public list; (2) network type — ASN-fingerprint classification across five categories (hosting/datacenter, residential ISP, CDN, cloud infrastructure or unknown). Detecting commercial VPNs by ASN is deliberately cautious: providers rotate ranges every few months, paid lists go stale, and a false «it’s a VPN» does more damage to a customer than an honest «network type: hosting.» The output is a clear label with a confidence level for the detection, never claiming what the backend can’t prove.
