IPDebrief

45.138.0.37

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 45.138.0.37/32

Classification: Low Risk Infrastructure IP

Date Generated: 2026-07-25

Analyst: IPDebrief SOC Intelligence Team

---

## Executive Summary

IP 45.138.0.37 is a low-risk infrastructure address belonging to Direct Cursus Technology Network Operations Centre (ASN 207304). The IP resolves to a Yandex spider hostname, operates with no open services (firewalled), and shows minimal threat indicators. Neighborhood analysis confirms the broader subnet maintains a low-risk profile with zero abuse density.

---

## Ownership & Network Infrastructure

FieldValue
**Organization**Direct Cursus Technology Network Operations Centre
**ASN**207304
**Network**DIRECTCURSUS-45-138-0-32 (45.138.0.32/28)
**RIR**ARIN
**Abuse Contact**noc@directcursuscst.com

The IP is part of a /28 block with four total sibling addresses. The subnet exhibits zero abuse density, indicating a generally benign infrastructure environment.

---

## Geolocation Analysis

Geolocation data shows inconsistencies across sources:

The geoPlausible flag is false, suggesting some location data may be inferred. The operator score is rated "Basic" (0.3478). Traceroute shows 21 hops with Comcast as a transit network.

---

## DNS & Resolution

MetricValue
**PTR Hostname**45-138-0-37.spider.yandex.com
**Forward Resolution**Confirmed (yandex.com)
**Forward Hostnames**1 unique entry
**DNSSEC**Valid
**CAA Records**Present

The reverse DNS points to a Yandex spider service hostname, consistent with infrastructure hosting Yandex search/scraping operations.

---

## Threat Indicators

CategoryStatus
**Risk Score**25 (Low Risk)
**Blacklist Count**0
**DNSBL Listed**1 of 8 lists
**Known Attacker**False
**Tor Exit Node**False
**Spam Source**False
**Threat Persistence**0 days

No active threat indicators detected. The single DNSBL listing represents minimal exposure. No known campaigns or correlated IPs observed.

---

## Services & Network Role

The absence of open services suggests this is a control plane or management IP rather than an endpoint exposing services.

---

## Neighborhood Analysis (45.138.0.0/24)

Neighbor IPRisk ScoreAuthority Score
45.138.0.33050
45.138.0.352560
45.138.0.362560

Risk Distribution: 0 High / 0 Medium / 3 Low

Abuse Density: 0%

Active Siblings: 0 threat-related

The neighborhood shows consistent low-risk behavior across all sibling addresses.

---

## Observation History

17 total observations recorded, with recent activity from 2026-07-25. Key observations include:

---

## Recommended Actions

SOC Analyst Guidance:

The IP exhibits characteristics of legitimate infrastructure hosting Yandex services. No evidence of malicious activity or abuse patterns. Monitor for changes in DNS resolution or service exposure.

---

Data Sources: IPDebrief Intelligence Platform

Confidence Level: High (Multiple validation sources)

Last Updated: 2026-07-25

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇦🇪 United Arab Emirates
RegionVirginia
CityAshburn
TimezoneAsia/Dubai
Latitude23.42
Longitude53.85

🏢 Ownership & Registration

OrganizationDirect Cursus Technology Network Operations Centre
ASNAS207304
Network NameDIRECTCURSUS-45-138-0-32
CIDR Block45.138.0.32/28
RIRARIN
CountryKZ
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR45-138-0-37.spider.yandex.com
Forward ConfirmedYes — FCrDNS verified
Forward Hostnames45-138-0-37.spider.yandex.com

🔐 DNS Hygiene

Hygiene Score100% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAAPresent

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown — Insufficient routing data to classify
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Server—
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS207304
Network Prefix45.138.0.0/24
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
28%
25
routing
8%
11
services
12%
22
ownership
17%
23
reputation
14%
13
geolocation
12%
22
Overall15%1016
Coverage: 6/6 dimensions · Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

📅 Observation Timeline 🔄 Live

First Seen2026-07-09 01:19:49 UTC
Last Seen2026-08-30 01:39:10 UTC
Profile Built2026-08-26 18:06:42 UTC
Data FreshnessLive
Signal Types22
Total Observations23
🔍 22 signal types · 23 observations collected
This report is generated from 22+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 45.138.0.37

Who owns the IP address 45.138.0.37?

45.138.0.37 is registered to Direct Cursus Technology Network Operations Centre. The address falls within the 45.138.0.32/28 network block. Registration is held at ARIN.

Where is 45.138.0.37 located?

Geolocation data places 45.138.0.37 in Ashburn, Virginia, United Arab Emirates. The local time zone is Asia/Dubai. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 45.138.0.37 malicious or safe?

45.138.0.37 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.

What is the hostname for 45.138.0.37?

The reverse DNS (PTR) record for 45.138.0.37 is 45-138-0-37.spider.yandex.com. This hostname is forward-confirmed, meaning it resolves back to the same address.

🏘️ Related IP Addresses

Nearby addresses in 45.138.0.32/28

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.