# IP Intelligence Briefing: 45.117.104.205/32
Classification: Moderate Risk (Score: 40/100)
Date of Analysis: 2026-07-23
Intel Source: IPDebrief Threat Intelligence Platform
## Executive Summary
IP 45.117.104.205 is a static residential/business endpoint (ebonenet.com) with moderate risk exposure. The address exhibits conflicting geolocation signals, limited threat persistence, and has been flagged on DNSBL infrastructure despite showing zero open services. Recommended for defensive filtering.
## Ownership & Network Infrastructure
| Attribute | Value |
|---|---|
| ASN | 150697 |
| Organization | IRT-EBONE1-PK |
| Netname | SNFIBER |
| RIR | ARIN |
| CIDR Block | 45.117.104.0/24 |
| DNS PTR | static-205-104-117-45.ebonenet.com |
Network Classification: Infrastructure endpoint with no active services detected. Port scanning indicates firewalled/no services. No TLS certificates or HTTP endpoints observed.
## Geolocation Analysis
Conflicting geolocation data detected across multiple sources:
- Primary Profile: GB (London, Europe/London timezone)
- Threat Feeds: Pakistan (latitude 30, longitude 70)
This discrepancy warrants attention during incident correlation. Multiple geo-source validations returned inconsistent consensus.
## Threat Indicators
- Risk Score: 40 (Moderate Risk)
- Abuse Confidence Score: Not explicitly scored in profile
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- DNSBL Listings: 2 of 8 total lists flagged with maximum severity: high
- Threat Observation Count: 1
- Threat Persistence Days: 0
- Persistently Malicious: False
## Observation History (18 Signals)
Recent activity includes:
- 2026-07-23 13:16:07: Threat indicator from Alienvault OTX (pulse count: 1)
- 2026-07-23 13:15:32: Geolocation signal from MaxMind Geolite2 (country: PK)
- 2026-07-23 13:15:24: DNSBL listings confirmed (8 total lists, 2 active with high severity)
- 2026-07-23 13:15:21: Domain association confirmed (ebonenet.com)
## Neighborhood Assessment
| Metric | Value |
|---|---|
| Subnet | 45.117.104.205/24 |
| Neighbor Count | 0 |
| Abuse Density | 0 |
| High-Risk Siblings | 0 |
| Threat Siblings | 0 |
No sibling IPs detected in the /24 subnet with elevated risk profiles.
## Relationship Graph
- Same Network: SNFIBER (multiple associations)
- DNS Associations: static-205-104-117-45.ebonenet.com
No organizational or certificate relationships beyond network and DNS associations.
## Recommended Defensive Actions
Firewall Rules (High Confidence):
```bash
# iptables
iptables -A INPUT -s 45.117.104.205 -j DROP
# nftables
nft add rule inet filter input ip saddr 45.117.104.205 drop
# nginx
deny 45.117.104.205;
# pfSense
45.117.104.205/32
# Cloudflare WAF
{"description":"Block 45.117.104.205 — IPDebrief risk score 40","action":"block","filter":{"expression":"ip.src eq 45.117.104.205"}}
# AWS WAF
{"Addresses":["45.117.104.205/32"],"Description":"IPDebrief risk 40"}
```
## Analyst Notes
1. Geolocation Discrepancy: The conflict between GB and PK geolocation signals requires correlation with other telemetry before definitive geolocation assignment.
2. Limited Service Exposure: No open ports or active services detected suggests this endpoint may be used for outbound-only communication or is intentionally hardened.
3. DNSBL Presence: Despite zero blacklist count in the primary profile, DNSBL evidence shows 2 high-severity listings across 8 total lists. This warrants monitoring.
4. Moderate Risk Profile: Risk score of 40 indicates the IP warrants defensive filtering but does not represent an immediate, high-severity threat.
5. Static Endpoint: The ebonenet.com PTR hostname suggests this is a residential or static business IP rather than a dynamic or datacenter endpoint.
Recommendation: Implement firewall blocking per rules above. Monitor for continued threat feed activity and geolocation consistency. Re-evaluate if this IP begins showing increased threat signals or service exposure.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Naseh Raoon |
| ASN | AS150697 |
| Network Name | SNFIBER |
| CIDR Block | 45.117.104.0/24 |
| RIR | ARIN |
| Country | PK |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | static-205-104-117-45.ebonenet.com |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | static-205-104-117-45.ebonenet.com |
🔐 DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS150697 |
| Network Prefix | 45.117.104.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 39% | 2 | 5 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 22% | 1 | 4 |
| geolocation | 8% | 1 | 1 |
| Overall | 19% | 9 | 16 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-04 17:24:28 UTC |
| Last Seen | 2026-09-11 08:17:25 UTC |
| Profile Built | 2026-09-11 08:32:36 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 28 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 45.117.104.205
Who owns the IP address 45.117.104.205?
45.117.104.205 is registered to Naseh Raoon. The address falls within the 45.117.104.0/24 network block. Registration is held at ARIN.
Where is 45.117.104.205 located?
Geolocation data places 45.117.104.205 in London, ENG, United Kingdom. The local time zone is Europe/London. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 45.117.104.205 malicious or safe?
45.117.104.205 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 45.117.104.205?
The reverse DNS (PTR) record for 45.117.104.205 is static-205-104-117-45.ebonenet.com. This hostname is not forward-confirmed, so it should be treated as a weak signal.