# IP Intelligence Briefing: 45.138.0.37/32
Classification: Low Risk Infrastructure IP
Date Generated: 2026-07-25
Analyst: IPDebrief SOC Intelligence Team
---
## Executive Summary
IP 45.138.0.37 is a low-risk infrastructure address belonging to Direct Cursus Technology Network Operations Centre (ASN 207304). The IP resolves to a Yandex spider hostname, operates with no open services (firewalled), and shows minimal threat indicators. Neighborhood analysis confirms the broader subnet maintains a low-risk profile with zero abuse density.
---
## Ownership & Network Infrastructure
| Field | Value |
|---|---|
| **Organization** | Direct Cursus Technology Network Operations Centre |
| **ASN** | 207304 |
| **Network** | DIRECTCURSUS-45-138-0-32 (45.138.0.32/28) |
| **RIR** | ARIN |
| **Abuse Contact** | noc@directcursuscst.com |
The IP is part of a /28 block with four total sibling addresses. The subnet exhibits zero abuse density, indicating a generally benign infrastructure environment.
---
## Geolocation Analysis
Geolocation data shows inconsistencies across sources:
- Primary consensus: UAE (Dubai area, 23.42°N, 53.85°E)
- Secondary reports: Kazakhstan, Virginia/Ashburn
The geoPlausible flag is false, suggesting some location data may be inferred. The operator score is rated "Basic" (0.3478). Traceroute shows 21 hops with Comcast as a transit network.
---
## DNS & Resolution
| Metric | Value |
|---|---|
| **PTR Hostname** | 45-138-0-37.spider.yandex.com |
| **Forward Resolution** | Confirmed (yandex.com) |
| **Forward Hostnames** | 1 unique entry |
| **DNSSEC** | Valid |
| **CAA Records** | Present |
The reverse DNS points to a Yandex spider service hostname, consistent with infrastructure hosting Yandex search/scraping operations.
---
## Threat Indicators
| Category | Status |
|---|---|
| **Risk Score** | 25 (Low Risk) |
| **Blacklist Count** | 0 |
| **DNSBL Listed** | 1 of 8 lists |
| **Known Attacker** | False |
| **Tor Exit Node** | False |
| **Spam Source** | False |
| **Threat Persistence** | 0 days |
No active threat indicators detected. The single DNSBL listing represents minimal exposure. No known campaigns or correlated IPs observed.
---
## Services & Network Role
- Open Ports: None detected
- Status: Firewalled / No Services
- Infrastructure Type: Not CDN, Cloud, Proxy, or Hosting
- Classification: Standard infrastructure IP
The absence of open services suggests this is a control plane or management IP rather than an endpoint exposing services.
---
## Neighborhood Analysis (45.138.0.0/24)
| Neighbor IP | Risk Score | Authority Score |
|---|---|---|
| 45.138.0.33 | 0 | 50 |
| 45.138.0.35 | 25 | 60 |
| 45.138.0.36 | 25 | 60 |
Risk Distribution: 0 High / 0 Medium / 3 Low
Abuse Density: 0%
Active Siblings: 0 threat-related
The neighborhood shows consistent low-risk behavior across all sibling addresses.
---
## Observation History
17 total observations recorded, with recent activity from 2026-07-25. Key observations include:
- Consistent ownership attribution to Direct Cursus Technology
- Geolocation signals show variation between UAE and Kazakhstan
- Operator scores remain stable at Basic level
- No significant threat signal changes observed
---
## Recommended Actions
SOC Analyst Guidance:
- Monitor Level: Standard (Low Risk)
- Firewall Rules: No specific blocking required; traffic appears legitimate infrastructure
- Alerting: No immediate alerting thresholds triggered
- Investigation Priority: Low
The IP exhibits characteristics of legitimate infrastructure hosting Yandex services. No evidence of malicious activity or abuse patterns. Monitor for changes in DNS resolution or service exposure.
---
Data Sources: IPDebrief Intelligence Platform
Confidence Level: High (Multiple validation sources)
Last Updated: 2026-07-25
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Direct Cursus Technology Network Operations Centre |
| ASN | AS207304 |
| Network Name | DIRECTCURSUS-45-138-0-32 |
| CIDR Block | 45.138.0.32/28 |
| RIR | ARIN |
| Country | KZ |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | 45-138-0-37.spider.yandex.com |
| Forward Confirmed | Yes — FCrDNS verified |
| Forward Hostnames | 45-138-0-37.spider.yandex.com |
🔐 DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS207304 |
| Network Prefix | 45.138.0.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 5 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 17% | 2 | 3 |
| reputation | 14% | 1 | 3 |
| geolocation | 12% | 2 | 2 |
| Overall | 15% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-09 01:19:49 UTC |
| Last Seen | 2026-08-30 01:39:10 UTC |
| Profile Built | 2026-08-26 18:06:42 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 23 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 45.138.0.37
Who owns the IP address 45.138.0.37?
45.138.0.37 is registered to Direct Cursus Technology Network Operations Centre. The address falls within the 45.138.0.32/28 network block. Registration is held at ARIN.
Where is 45.138.0.37 located?
Geolocation data places 45.138.0.37 in Ashburn, Virginia, United Arab Emirates. The local time zone is Asia/Dubai. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 45.138.0.37 malicious or safe?
45.138.0.37 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 45.138.0.37?
The reverse DNS (PTR) record for 45.138.0.37 is 45-138-0-37.spider.yandex.com. This hostname is forward-confirmed, meaning it resolves back to the same address.