Is 91.132.144.59 a VPN? Yes — Tor.
Ground-truth confirmed VPN/proxy — 5 signals matched across 4 intelligence sources. very high confidence in this reading.
Network identity
Location
BGP / prefix
Report abuse
IP intelligence
Matches against the Tor exit list, public proxy feeds, curated VPN-provider ranges, and datacenter ASN registries.
Published Tor exit relay (check.torproject.org bulk exit list)
IP on public open-proxy feed(s): firehol-anonymizers
ASN classification
Team Cymru allocation data + PeeringDB self-declared network type.
PeeringDB classifies ASN AS197540 as "Content" — content/cloud-hosting profile
BGP routing topology
RIPE NCC routing-information service. Single-homed ASes and unannounced prefixes.
ASN AS197540 is single-homed (1 upstream, 1 total neighbours) — lone-wolf BGP footprint common to proxy-operator ASes
Shodan observation
Passive ~30-day port fingerprint. VPN/proxy software CPE matches and observed ports.
Shodan has observed 3 open port(s) on this IP
Why this IP is flagged — sources that matched
Every list, feed, or live probe that confirmed the verdict above. Cross-source agreement is what makes this verdict trustworthy — most competitors hide their sources entirely.
- X4BNet VPN aggregatorrefresh: every 24h
Community-maintained CIDR feed covering ProtonVPN, NordVPN, ExpressVPN, CyberGhost, TorGuard, TunnelBear, AtlasVPN, Hotspot Shield, and others whose own APIs became auth-walled.
- firehol-anonymizersrefresh: —