THREAT INTELLIGENCE BRIEFING
Target IP: 45.135.198.244/32
Classification: HIGH RISK
Date: 2026-07-23
---
EXECUTIVE SUMMARY
IP address 45.135.198.244 is classified as HIGH RISK with an overall risk score of 80/100. The IP is located in Spain (ES) with geolocation data indicating Madrid/Andalusia region. The address belongs to BGP prefix 45.135.198.0/24 under ASN 202375. No open services or active ports are detected; the service purpose is reported as "Firewalled / No Services."
OWNERSHIP & INFRASTRUCTURE
- ASN: 202375
- BGP Prefix: 45.135.198.0/24
- Organization: es-digitalbox-1-mnt
- Abuse Contact: digitalboxwifi@gmail.com
- RIR: ARIN
- Route Stability: Unstable (isRouteStable: false)
- DNSSEC: Valid
- Cloud/CDN/Proxy: No
THREAT INDICATORS
- Risk Score: 80/100 (High)
- Blacklist Status: Listed on 8 DNSBLs (4 active lists)
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Abuse Confidence Score: Not available
- Campaign Correlation: No known campaign matches
NETWORK BEHAVIOR
- Open Ports: None detected
- DNS Resolution: Forward resolution failed (0 forward hostnames)
- PTR Records: None
- Traceroute: 15 hops, 5 timed out, final hop via Comcast
- Behavioral Signals: No honeypot hits, WAF violations, or enumeration strikes
- Total Incidents: 0
- Active Attacker Status: False
NEIGHBORHOOD ANALYSIS
- Subnet: 45.135.198.0/24
- Abuse Density: 0.091 (9.1% - moderate)
- Total Siblings: 11
- Risk Distribution:
- High Risk: 1 (45.135.198.50)
- Medium Risk: 6 (score 40)
- Low Risk: 4 (score 0)
- Notable Neighbor: 45.135.198.50 also exhibits high risk (80/100)
OBSERVATION HISTORY
11 observations recorded, most recent 2026-07-23. Signals include organization attribution (es-digitalbox-1-mnt), geographic data (Albox, Andalusia, Spain), and routing information. Geolocation shows discrepancy between profile (Madrid) and historical data (Albox).
RELATIONSHIP GRAPH
No relationships detected to related entities (subnets, hostnames, organizations, certificates).
---
RECOMMENDED ACTIONS
Immediate:
- Increase logging verbosity for traffic from this IP
- Apply blocking rules at perimeter firewall
Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 45.135.198.244 -j DROP
# nftables
nft add rule inet filter input ip saddr 45.135.198.244 drop
# nginx
deny 45.135.198.244;
```
Cloud Provider Integration:
- Cloudflare WAF: Block IP (expression: ip.src eq 45.135.198.244)
- AWS WAF: Add 45.135.198.244/32 to blacklist
Additional Context:
The IP subnet (45.135.198.0/24) exhibits moderate abuse density (9.1%) with one additional high-risk neighbor (45.135.198.50). Consider blocking the entire /24 prefix if traffic patterns warrant it. Monitor for any changes in risk profile or emergence of threat indicators.
Confidence Level: High (based on DNSBL listings and risk scoring)
Classification: Defensive Security Intelligence
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | es-digitalbox-1-mnt |
| ASN | AS202375 |
| Network Name | ES-DIGITALBOX-20190731 |
| CIDR Block | 45.135.196.0/22 |
| RIR | ARIN |
| Country | ES |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | — |
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 80, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS202375 |
| Network Prefix | 45.135.198.0/24 |
| Route mapping | Found |
| HSTS | Not detected |
| CSP | Not detected |
| HTTP/2 | Not detected |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 13% | 1 | 1 |
| routing | 13% | 1 | 1 |
| services | 13% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 6% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-05 23:58:40 UTC |
| Last Seen | 2026-08-27 00:26:29 UTC |
| Profile Built | 2026-08-29 06:50:38 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 21 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 45.135.198.244
Who owns the IP address 45.135.198.244?
45.135.198.244 is registered to es-digitalbox-1-mnt. The address falls within the 45.135.196.0/22 network block. Registration is held at ARIN.
Where is 45.135.198.244 located?
Geolocation data places 45.135.198.244 in Albox, Andalusia, Spain. The local time zone is Europe/Madrid. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 45.135.198.244 malicious or safe?
45.135.198.244 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 45.135.198.244?
Responsive ports observed on 45.135.198.244 include 443, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.