# IP INTELLIGENCE BRIEFING
Target: 45.112.71.244/32
Date: 2026-07-29
Classification: HIGH RISK
## EXECUTIVE SUMMARY
IP address 45.112.71.244 presents a HIGH RISK profile (Score: 80/100) associated with infrastructure provider ALLIANCEBROADBAND-IN (ASN: 23860) in Kolkata, West Bengal, India. The IP is listed on 4 of 8 DNSBL entries with high-severity ratings, indicating active reputation compromise. No persistent malicious indicators or known campaign associations were identified.
---
## TECHNICAL PROFILE
Ownership & Infrastructure
| Attribute | Value |
|---|---|
| **ASN** | 23860 (Sk Akramul Alam) |
| **Netname** | ALLIANCEBROADBAND-IN |
| **CIDR Block** | 45.112.68.0/22 |
| **Geolocation** | Kolkata, West Bengal, IN |
| **Registration** | ARIN |
| **Service Type** | Single-Service Host |
Network Services
- Port 80/TCP: HTTP (freenginx/1.28.0)
- PTR Record: node-45-112-71-244.alliancebroadband.in
- Forward Resolution: 1 hostname (alliancebroadband.in)
- SSL/TLS: Not configured
Control Plane Indicators
- Route Stability: False (0 route changes in 30 days)
- RPKI State: Not available
- DNSSEC: Valid
- DNSBL Listings: 4 of 8 total lists
---
## THREAT ASSESSMENT
Risk Indicators
- Reputation Score: 80/100 (HIGH RISK)
- DNSBL Status: Listed on 4 blacklists with high-severity ratings
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Campaign Association: None identified
Historical Activity
- Observations: 17 total signals recorded
- Recent Activity: 2026-07-29 showed DNSBL listings with high severity
- Ownership Persistence: No ownership changes detected
- Threat Persistence: Not persistently malicious
---
## NEIGHBORHOOD ANALYSIS
Subnet: 45.112.71.0/24
| Neighbor IP | Risk Score | Authority Score | Classification |
|---|---|---|---|
| 45.112.71.84 | 55 | 50 | Medium |
| 45.112.71.87 | 30 | 50 | Low |
| 45.112.71.109 | 55 | 50 | Medium |
Abuse Density: 0
Total Siblings: 3
---
## RELATIONSHIP GRAPH
- Network Associations: ALLIANCEBROADBAND-IN (3 instances)
- DNS Associations: node-45-112-71-244.alliancebroadband.in (3 instances)
---
## RECOMMENDED ACTIONS
Immediate Mitigation
1. Increase Logging: Enable verbose logging for all traffic from this IP
2. Block at Perimeter: Implement firewall rules across all security layers
Firewall Implementation
```bash
# iptables
iptables -A INPUT -s 45.112.71.244 -j DROP
# nftables
nft add rule inet filter input ip saddr 45.112.71.244 drop
# nginx
deny 45.112.71.244;
# pfSense
45.112.71.244/32
# Cloudflare WAF
Block 45.112.71.244 โ IPDebrief risk score 80
# AWS WAF
Addresses: ["45.112.71.244/32"]
Description: IPDebrief risk 80
```
---
## INTELLIGENCE NOTES
- The IP operates as a single-service host with HTTP services on port 80
- DNSBL listings suggest the IP has been flagged for abuse activity
- No correlation to known APT campaigns or coordinated attacks
- Neighbor IPs in the /24 subnet show moderate risk scores (30-55), suggesting this may be an isolated incident within the broader infrastructure
Analyst Recommendation: Implement blocking while maintaining audit trails. Monitor for any changes in behavior or additional DNSBL listings.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Sk Akramul Alam |
| ASN | AS23860 |
| Network Name | ALLIANCEBROADBAND-IN |
| CIDR Block | 45.112.68.0/22 |
| RIR | ARIN |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | node-45-112-71-244.alliancebroadband.in |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | node-45-112-71-244.alliancebroadband.in |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| Closed Ports | 22, 25, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | freenginx/1.28.0 |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 4% | 1 | 2 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-23 13:57:07 UTC |
| Last Seen | 2026-07-30 11:04:04 UTC |
| Profile Built | 2026-07-29 19:13:35 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 21 |
Full dossier details are available via our API.