# INTELLIGENCE BRIEFING: 45.156.87.162/32
Classification: Moderate Risk | Date: 2026-07-23 | Priority: Medium-High
---
## EXECUTIVE SUMMARY
IP address 45.156.87.162 presents a moderate risk profile with a risk score of 65/100. The address is part of the 45.156.87.0/24 subnet operated by TechTies-Inc (ASN 197170). The subnet exhibits mixed abuse characteristics with an abuse density of 11.4%, indicating 10 threat-sibling IPs among 22 active siblings. The target IP shows no open services but has been DNSBL-listed on 3 of 8 threat feeds.
---
## TECHNICAL PROFILE
| Attribute | Value |
|---|---|
| **IP Address** | 45.156.87.162/32 |
| **Risk Score** | 65/100 |
| **ASN** | 197170 |
| **Organization** | mnt-nl-skylink2-1 / TechTies-Inc |
| **Network Block** | 45.156.87.0/24 |
| **Geolocation** | NL (Netherlands), Limburg, Eygelshoven |
| **Timezone** | Europe/Amsterdam |
| **DNSBL Listings** | 3/8 lists |
| **Service Status** | Firewalled / No Services |
---
## THREAT INDICATORS
- Known Attacker: No | Tor Exit Node: No | Spam Source: No
- Campaign Correlation: No active campaigns detected
- Certificate Matches: 0 | Banner Matches: 0
- Threat Feeds: No specific threat indicators identified
---
## NEIGHBORHOOD ANALYSIS
The 45.156.87.0/24 subnet contains 36 sibling IPs with the following risk distribution:
- High Risk (80+): 4 IPs (45.156.87.34, 45.156.87.147, 45.156.87.165, 45.156.87.234)
- Medium-High Risk (65): 10 IPs including target (45.156.87.162, 45.156.87.13, 45.156.87.93, 45.156.87.166, 45.156.87.182, 45.156.87.204, 45.156.87.216, 45.156.87.253, 45.156.87.254)
- Low Risk (<65): 19 IPs
Subnet Classification: Mixed abuse profile. Target IP shares network infrastructure with multiple high-risk neighbors, suggesting potential for coordinated abuse or misconfigured infrastructure.
---
## OBSERVATION HISTORY
Recent monitoring indicates:
- SSH Service Detected: OpenSSH 9.6p1 Ubuntu-3ubuntu13.15 observed (confidence: 90%)
- Geolocation Signals: Confirmed Netherlands origin (confidence: 52%)
- Registration Signals: ARIN-registered to TechTies-Inc (confidence: 95%)
- Blacklist Activity: 3 DNSBL listings detected with maximum severity: "high"
- Persistence: Single threat observation recorded; not persistently malicious
---
## NETWORK TRAFFIC CHARACTERISTICS
- Traceroute: 14 hops, 4 timed out, transit networks include Comcast
- Route Stability: False (route changes detected)
- BGP Prefix: 45.156.87.0/24
- RTT: 0.1ms (first hop) to 115.2ms (last hop)
---
## RECOMMENDED ACTIONS
Immediate Actions:
1. Logging Enhancement: Increase logging verbosity for all traffic from this IP
2. Ingress Filtering: Block at perimeter firewall
3. Subnet Monitoring: Monitor adjacent high-risk IPs for correlated activity
Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 45.156.87.162 -j DROP
# nftables
nft add rule inet filter input ip saddr 45.156.87.162 drop
# Cloudflare WAF
ip.src eq 45.156.87.162 → BLOCK
```
---
## ANALYST NOTES
The target IP (45.156.87.162) shows no active services but maintains a moderate risk profile due to subnet-level abuse characteristics. The presence of 4 high-risk neighbors within the same /24 suggests this infrastructure may be misconfigured or shared with malicious actors. Recommend blocking at perimeter level while maintaining observation for pattern correlation. No immediate threat indicators (TOR, spam, known campaigns) detected, but DNSBL listings warrant continued monitoring.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | mnt-nl-skylink2-1 |
| ASN | AS197170 |
| Network Name | TechTies-Inc |
| CIDR Block | 45.156.87.0/24 |
| RIR | ARIN |
| Country | NL |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | ship-behind.vmheaven.io |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | ship-behind.vmheaven.io |
🔐 DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | 3/3 domains |
| DMARC | 2/3 domains |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
| Domains Checked | 3 domains |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 443 | https | tcp | — |
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS197170 |
| Network Prefix | 45.156.87.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 17% | 2 | 4 |
| ownership | 17% | 2 | 3 |
| reputation | 28% | 1 | 7 |
| geolocation | 23% | 2 | 3 |
| Overall | 20% | 10 | 21 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-03 16:58:24 UTC |
| Last Seen | 2026-09-29 20:39:29 UTC |
| Profile Built | 2026-09-29 21:14:28 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 55 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 45.156.87.162
Who owns the IP address 45.156.87.162?
45.156.87.162 is registered to mnt-nl-skylink2-1. The address falls within the 45.156.87.0/24 network block. Registration is held at ARIN.
Where is 45.156.87.162 located?
Geolocation data places 45.156.87.162 in Eygelshoven, Limburg, Netherlands. The local time zone is Europe/Amsterdam. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 45.156.87.162 malicious or safe?
45.156.87.162 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 45.156.87.162?
The reverse DNS (PTR) record for 45.156.87.162 is ship-behind.vmheaven.io. This hostname is not forward-confirmed, so it should be treated as a weak signal.
What ports are open on 45.156.87.162?
Responsive ports observed on 45.156.87.162 include 80, 443, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.