# IP Intelligence Briefing: 145.90.106.69
Classification: Dormitory Network IP โ Low Active Threat Profile
Risk Score: 50 (Moderate)
Report Date: 2026-07-30
Analyst: IPDebrief Intelligence
---
## 1. Executive Summary
IP 145.90.106.69 is a residential dormitory network address associated with the University of Utrecht (UU-dormitory-net) in Rotterdam, Netherlands. The IP exhibits moderate risk scoring (50) but currently demonstrates low active threat indicators. No open services, no known malicious campaigns, and a clean subnet classification. Recommend monitoring but no immediate blocking required unless additional threat signals emerge.
---
## 2. Ownership & Geolocation
| Attribute | Value |
|---|---|
| **ASN** | 1103 (IRT-SURFcert) |
| **Organization** | UU-dormitory-net (University of Utrecht) |
| **CIDR Block** | 145.90.64.0/18 |
| **Location** | Rotterdam, South Holland, Netherlands (NL) |
| **Coordinates** | 52.13°N, 5.29°E |
| **Timezone** | Europe/Amsterdam |
---
## 3. Threat Assessment
Current Threat Indicators: None
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0
- Abuse Confidence Score: Not available
Network Classification:
- Infrastructure Type: Firewalled / No Services
- Open Ports: None detected
- Cloud/CDN/Proxy: No
- Residential: Yes (dormitory network)
DNS Analysis:
- PTR Hostname: 69pc106.sshunet.nl
- Forward Resolution: Confirmed (69pc106.sshunet.nl)
- Email Auth: SPF enabled, DMARC not configured
---
## 4. Neighborhood & Contextual Risk
Subnet: 145.90.106.69/24
- Abuse Density: 0 (Clean)
- Active Siblings: 0
- Threat Siblings: 0
- Classification: Clean
Assessment: The IP resides in a dormitory subnet with no observed abuse. No adjacent IPs flagged as malicious. This suggests the moderate risk score (50) is baseline rather than indicative of active malicious behavior.
---
## 5. Historical Observations (17 Total)
Recent Activity Window: 2026-07-30
Signal History:
- Geolocation Signals: Consistent NL localization with plausible geo validation (155.3 km distance from claimed coordinates)
- Network Signals: Stable ownership, no ownership changes
- Behavioral Signals: No honeypot hits, no enumeration strikes
- Threat Persistence: 0 days (not persistently malicious)
Trend Analysis: Stable profile with no escalation of threat signals. The IP has shown consistent residential/network classification with no degradation in risk posture.
---
## 6. Related Entities
DNS Associations: 69pc106.sshunet.nl (multiple records)
Network Associations: UU-dormitory-net (multiple references)
Assessment: All relationships point to legitimate university dormitory infrastructure. No suspicious external connections or certificate associations detected.
---
## 7. Recommended Actions
Risk-Based Recommendations:
| Platform | Action |
|---|---|
| **iptables** | `iptables -A INPUT -s 145.90.106.69 -j DROP` |
| **nftables** | `nft add rule inet filter input ip saddr 145.90.106.69 drop` |
| **nginx** | `deny 145.90.106.69;` |
| **pfSense** | `145.90.106.69/32` |
| **Cloudflare WAF** | Block IP with expression: `ip.src eq 145.90.106.69` |
| **AWS WAF** | Add address `145.90.106.69/32` |
Note: Recommendations provided are probabilistic. Given the IP's dormitory network context and clean subnet classification, blocking may be overly restrictive. Consider:
- Monitor only if organization has strict residential IP policies
- Allow with logging to observe activity patterns
- Block only if specific threat indicators are confirmed
---
## 8. Analyst Assessment
Threat Level: LOW
Confidence: MEDIUM
IP 145.90.106.69 represents a dormitory network address with no active threat indicators. The moderate risk score (50) appears to be a baseline classification rather than indicative of malicious activity. The subnet is clean with no abuse density, and the IP shows no historical threat persistence.
Recommended SOC Actions:
1. Add to watchlist for trend monitoring
2. No immediate blocking required
3. Investigate only if additional threat signals emerge
4. Consider organizational policy regarding residential IP traffic
Next Review: Monitor for changes in threat indicators or subnet abuse patterns.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-SURFcert |
| ASN | AS1103 |
| Network Name | UU-dormitory-net |
| CIDR Block | 145.90.64.0/18 |
| RIR | RIPE |
| Country | NL |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 69pc106.sshunet.nl |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | 69pc106.sshunet.nl |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-dropbear_2012.55 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-29 10:33:27 UTC |
| Last Seen | 2026-07-31 07:30:35 UTC |
| Profile Built | 2026-07-30 21:08:47 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 21 |
Full dossier details are available via our API.