# IP INTELLIGENCE BRIEFING: 45.156.87.12
Classification: Moderate Risk | Status: Active Monitoring Recommended
## Executive Summary
IP 45.156.87.12 is classified as Moderate Risk with a risk score of 40/100. The address is associated with TechTies-Inc (ASN 197170) and is located in Eygelshoven, Limburg, Netherlands. The IP is currently firewalled with no open services, but exhibits notable neighborhood activity with 7 threat siblings in the /24 subnet.
## Network Profile
| Attribute | Value |
|---|---|
| ASN | 197170 |
| Organization | TechTies-Inc |
| Netname | TechTies-Inc |
| CIDR Block | 45.156.87.0/24 |
| RIR | ARIN |
| Location | NL (Netherlands), Limburg, Eygelshoven |
| Service Status | Firewalled / No Services |
## Threat Indicators
- Risk Score: 40/100 (Moderate Risk)
- Abuse Confidence Score: Not available
- Blacklist Count: 0 (Control plane shows DNSBL listed: 2/8 total lists)
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Campaign Associations: None detected
- Threat Feeds: No matches
## Neighborhood Analysis (45.156.87.0/24)
The /24 subnet shows elevated activity with 36 total sibling IPs:
- Abuse Density: 19.44%
- Classification: Mostly Clean
- Active Siblings: 23/36
- Threat Siblings: 7
- Risk Distribution: High (4), Medium (13), Low (18)
Notable High-Risk Neighbors:
- 45.156.87.34 (Risk: 80)
- 45.156.87.147 (Risk: 80)
- 45.156.87.165 (Risk: 80)
- 45.156.87.234 (Risk: 80)
## Behavioral Observations
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: 0
- Route Stability: Unstable (is_route_stable: false)
- RPKI State: Unknown
- DNSSEC Valid: Yes
## Historical Trend
Analysis of 16 signal observations indicates stable characteristics:
- Geolocation: Consistent NL/Limburg/Eygelshoven placement
- Network Classification: Stable (mostly_clean classification maintained)
- Abuse Density: Consistent at ~0.1944 across observations
- Network RTT: 98-107ms average, consistent with claimed location
## Recommended Actions
Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 45.156.87.12 -j DROP
# nftables
nft add rule inet filter input ip saddr 45.156.87.12 drop
# nginx
deny 45.156.87.12;
```
WAF Integration:
- Cloudflare WAF: Block with expression `ip.src eq 45.156.87.12`
- AWS WAF: Add 45.156.87.12/32 to block list
## Intelligence Assessment
The target IP shows moderate risk with firewalled status and no active services. However, the 19.44% abuse density in the /24 and presence of 7 threat siblings indicates this may be part of a larger infrastructure. The subnet's mixed risk profile (4 high-risk neighbors) warrants monitoring of the full /24 range. No direct evidence of malicious activity from this specific IP, but neighborhood context suggests elevated threat posture.
Priority: Monitor | Recommended Action: Block at perimeter firewall, monitor subnet activity
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | mnt-nl-skylink2-1 |
| ASN | AS197170 |
| Network Name | TechTies-Inc |
| CIDR Block | 45.156.87.0/24 |
| RIR | ARIN |
| Country | NL |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | relief-burgey.vmheaven.io |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | relief-burgey.vmheaven.io |
🔐 DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS197170 |
| Network Prefix | 45.156.87.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 4% | 1 | 2 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-04 23:32:10 UTC |
| Last Seen | 2026-08-27 06:11:23 UTC |
| Profile Built | 2026-08-30 19:43:31 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 26 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 45.156.87.12
Who owns the IP address 45.156.87.12?
45.156.87.12 is registered to mnt-nl-skylink2-1. The address falls within the 45.156.87.0/24 network block. Registration is held at ARIN.
Where is 45.156.87.12 located?
Geolocation data places 45.156.87.12 in Eygelshoven, Limburg, Netherlands. The local time zone is Europe/Amsterdam. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 45.156.87.12 malicious or safe?
45.156.87.12 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 45.156.87.12?
The reverse DNS (PTR) record for 45.156.87.12 is relief-burgey.vmheaven.io. This hostname is not forward-confirmed, so it should be treated as a weak signal.
What ports are open on 45.156.87.12?
Responsive ports observed on 45.156.87.12 include 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.