IP INTELLIGENCE BRIEFING
Target: 199.45.154.125/32
Date: June 2026
Classification: Moderate Risk
---
**EXECUTIVE SUMMARY**
IP 199.45.154.125 is registered to Censys, Inc. (ASN 398722) and resolves to censys-scanner.com. The IP maintains a moderate risk score of 40 and operates within a high-abuse subnet (199.45.154.0/24) with 34 threat-associated siblings. No active services or open ports detected. The IP is listed on 2 of 8 DNSBLs and shows limited threat persistence (1 observation).
---
**OWNERSHIP & GEOLOCATION**
- Organization: Censys, Inc.
- ASN: 398722
- Country: United States (US)
- Region: New York (US-NY)
- Registration: ARIN
- DNS PTR: 125.154.45.199.censys-scanner.com
- Forward Resolution: Confirmed (censys-scanner.com)
---
**THREAT INDICATORS**
- Risk Score: 40/100 (Moderate)
- Blacklist Status: Listed on 2 of 8 DNSBLs
- Known Attacker: No
- Tor Exit: No
- Spam Source: No
- Known Campaigns: None detected
- Abuse Confidence: Not escalated beyond baseline
---
**NETWORK BEHAVIOR**
- Service Status: Firewalled / No Services Detected
- Open Ports: None
- TLS/Certificate: Not configured
- Connection Type: Infrastructure (No CDN/Proxy/VPN indicators)
- Cloud Provider: None detected
---
**SUBNET CONTEXT (199.45.154.0/24)**
- Total Siblings: 48
- Active Siblings: 30
- Threat Siblings: 34
- Abuse Density: 0.7083 (High Abuse Classification)
- Inherited Risk Score: 28
- Risk Distribution: 47 medium-risk IPs, 0 high-risk IPs
---
**OBSERVATION HISTORY**
- Total Observations: 22
- Threat Persistence: 0 days
- Recent Signals: Minimal threat activity detected (last observation: 2026-06-23)
- Trend: Stable with no escalation patterns
---
**RELATIONSHIPS**
- Network: CENSY (Same network association)
- DNS Hostnames: 125.154.45.199.censys-scanner.com
- Associated Entities: 34 relationship links identified
---
**RECOMMENDED ACTIONS**
Based on risk profile, the following defensive measures are recommended:
Firewall Rules:
- `iptables -A INPUT -s 199.45.154.125 -j DROP`
- `nft add rule inet filter input ip saddr 199.45.154.125 drop`
WAF Configuration:
- Cloudflare: Block with expression `ip.src eq 199.45.154.125`
- AWS WAF: Add to block list with address 199.45.154.125/32
---
**ANALYST NOTES**
This IP belongs to Censys scanning infrastructure operating in a high-abuse subnet. While the IP itself shows moderate risk and no active services, the subnet context suggests potential for scanning or reconnaissance activity. Consider blocking at perimeter, but verify against business requirements for Censys scanning operations. Monitor for changes in risk profile or emergence of active service indicators.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Censys, Inc. |
| ASN | AS398722 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 125.154.45.199.censys-scanner.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 125.154.45.199.censys-scanner.com |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 22% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:06 UTC |
| Last Seen | 2026-06-23 04:29:06 UTC |
| Profile Built | 2026-06-23 04:33:51 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 24 |
Full dossier details are available via our API.