IP Intelligence Briefing: 45.153.34.41
Executive Summary
IP address 45.153.34.41 is a moderately risky (65/100) endpoint associated with TechTies-Inc (ASN 197170) in Eygelshoven, Limburg, Netherlands. The IP is classified as firewalled with no active services and exhibits limited threat indicators, though it maintains 3 DNSBL listings across 8 total blacklist sources.
Ownership and Network Context
The IP is registered under ASN 197170 within the 45.153.34.0/24 block. Ownership data indicates organization "mnt-de-xsserver-1" with abuse contact available via RDAP. Registration occurred through ARIN. The control plane shows route instability (isRouteStable: false) with 0 route changes in the past 30 days.
Geolocation
Geolocation data places the endpoint in Eygelshoven, Limburg, Netherlands (coordinates: 51.68°N, 7.70°E), with 266 km accuracy radius. Geo validation indicates geoPlausible: false, suggesting potential location spoofing or data inconsistency.
Threat Profile
Current threat indicators show no active attack campaigns, no known attacker status, and no spam source classification. The IP is not a Tor exit node or proxy. However, 3 DNSBL listings were detected across 8 total lists, indicating prior reputation issues. Abuse confidence score was not provided in the profile.
Network Behavior
Network scanning revealed zero open ports. TLS certificate data, HTTP titles, and server banners are absent, consistent with the "Firewalled / No Services" classification. The IP shows no evidence of honeypot hits, enumeration strikes, or WAF violations.
Observation History
Twelve total observations were recorded. Recent signals (2026-07-27) confirmed ASN registration through ARIN, DNSSEC validation on the PTR record (41.34.153.45.in-addr.arpa), and multi-signal inference for geolocation. Three blacklist listings were observed with maximum severity of "high."
Subnet Analysis (45.153.34.0/24)
The /24 neighborhood contains 40 sibling IPs with an abuse density of 0.025. Risk distribution across the subnet: 1 high-risk, 26 medium-risk, and 13 low-risk IPs. Notable high-risk neighbors include 45.153.34.236 (risk: 80), 45.153.34.71 (risk: 65), 45.153.34.181 (risk: 65), and 45.153.34.235 (risk: 65).
Relationships
The relationship graph identifies one connection: TechTies-Inc (same network classification). No additional hostnames, organizations, or certificate associations were discovered.
Recommended Actions
Based on the elevated risk score (65/100), the following mitigations are recommended:
1. Monitoring: Increase logging verbosity and review recent activity from this IP.
2. Firewall Rules:
- iptables: `iptables -A INPUT -s 45.153.34.41 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 45.153.34.41 drop`
- nginx: `deny 45.153.34.41;`
- pfSense: `45.153.34.41/32`
- Cloudflare WAF: Block with expression `ip.src eq 45.153.34.41`
- AWS WAF: Configure rule for address `45.153.34.41/32`
Intelligence Assessment
While 45.153.34.41 does not exhibit active malicious behavior, its elevated risk score and blacklist presence warrant monitoring. The subnet shows moderate abuse density with multiple high-risk neighbors, suggesting the block may host compromised or misconfigured endpoints. Defensive blocking is recommended pending further correlation with incident data.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | mnt-de-xsserver-1 |
| ASN | AS197170 |
| Network Name | TechTies-Inc |
| CIDR Block | 45.153.34.0/24 |
| RIR | ARIN |
| Country | NL |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS197170 |
| Network Prefix | 45.153.34.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 4% | 1 | 1 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-14 21:58:55 UTC |
| Last Seen | 2026-09-02 22:56:39 UTC |
| Profile Built | 2026-08-28 22:36:39 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 20 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 45.153.34.41
Who owns the IP address 45.153.34.41?
45.153.34.41 is registered to mnt-de-xsserver-1. The address falls within the 45.153.34.0/24 network block. Registration is held at ARIN.
Where is 45.153.34.41 located?
Geolocation data places 45.153.34.41 in Eygelshoven, Limburg, Netherlands. The local time zone is Europe/Amsterdam. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 45.153.34.41 malicious or safe?
45.153.34.41 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 45.153.34.41?
Responsive ports observed on 45.153.34.41 include 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.