IP INTELLIGENCE BRIEFING: 37.49.225.44/32
Classification: Low Risk / Single-Service Host
---
Executive Summary:
IP address 37.49.225.44 presents a low-risk profile with a risk score of 0. The address operates as a single-service host in Amsterdam, Netherlands, with no current threat indicators, blacklist presence, or malicious activity observed. No actionable security rules are recommended at this time.
---
Ownership and Network Context:
- ASN: 61254 (ESTOXY-MNT)
- Network Name: ESTOXY-AMS1-DSRV-06
- CIDR Block: 37.49.225.0/24
- RIR: RIPE
- Delegation Age: 1,164 days (~3.2 years)
- Abuse Contact: abuse@estoxy.com (via RDAP)
Geolocation:
- Country: Netherlands (NL)
- City: Amsterdam
- Region: North Holland
- Coordinates: 52.13°N, 5.29°E
- Geo Consensus: Confirmed across 1 source
Network Classification:
- Type: Single-Service Host
- Not classified as: Cloud, CDN, VPN, Proxy, Tor, Hosting, Mobile, Residential, Bogon, or Anycast
---
Services and Ports:
- Open Port: TCP/22 (SSH)
- Banner: SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15
- DNS Resolution: No forward resolution detected
- Email Authentication: No SPF or DMARC records associated
---
Threat Indicators:
- Risk Score: 0
- Provider Score: 0
- Authority Score: 0
- Blacklist Count: 0
- Threat Feeds: None
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
---
Control Plane Data:
- BGP Origin ASN: 61254
- BGP Path: 2914 → 3920 → 61254
- Route Changes (30d): 1
- Route Stability: False
- RPKI State: Not validated
- DNSSEC: Valid
- DNSBL Listings: 0/8 total lists
---
Observation History (18 Signals):
- Threat Persistence: 0 days
- Threat Observation Count: 0
- Persistent Malicious Behavior: No
- Ownership Changes: 0
- Historical Signals: Recent observations (as of 2026-07-24) confirm stable network classification and geolocation data
---
Neighborhood Analysis:
- Subnet: 37.49.225.0/24
- Abuse Density: 0.0
- Neighbor Count: 0
- High/Medium/Low Risk Neighbors: 0/0/0
- Inherited Risk: 0
---
Relationships:
- Same Network: ESTOXY-AMS1-DSRV-06 (1 relationship)
- Related Entities: No additional hostnames, organizations, or certificates identified
---
Recommended Actions:
No specific firewall rules or mitigation recommendations are generated due to the low-risk profile. Standard monitoring practices are advised.
---
Intelligence Assessment:
This IP address represents a legitimate single-service host infrastructure with no evidence of malicious activity. The network exhibits normal BGP behavior with minimal route changes. SSH service is exposed but no exploitation attempts or threat indicators have been observed. No immediate action required; continue routine monitoring.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | ESTOXY-MNT |
| ASN | AS61254 |
| Network Name | ESTOXY-AMS1-DSRV-06 |
| CIDR Block | 37.49.225.0/24 |
| RIR | RIPE |
| Country | NL |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS61254 |
| Network Prefix | 37.49.225.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 4% | 1 | 1 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-07 12:35:35 UTC |
| Last Seen | 2026-08-29 01:36:00 UTC |
| Profile Built | 2026-08-29 01:53:28 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 21 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 37.49.225.44
Who owns the IP address 37.49.225.44?
37.49.225.44 is registered to ESTOXY-MNT. The address falls within the 37.49.225.0/24 network block. Registration is held at RIPE.
Where is 37.49.225.44 located?
Geolocation data places 37.49.225.44 in Amsterdam, North Holland, Netherlands. The local time zone is Europe/Amsterdam. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 37.49.225.44 malicious or safe?
37.49.225.44 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 37.49.225.44?
Responsive ports observed on 37.49.225.44 include 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.