IPDebrief

45.156.87.162

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# INTELLIGENCE BRIEFING: 45.156.87.162/32

Classification: Moderate Risk | Date: 2026-07-23 | Priority: Medium-High

---

## EXECUTIVE SUMMARY

IP address 45.156.87.162 presents a moderate risk profile with a risk score of 65/100. The address is part of the 45.156.87.0/24 subnet operated by TechTies-Inc (ASN 197170). The subnet exhibits mixed abuse characteristics with an abuse density of 11.4%, indicating 10 threat-sibling IPs among 22 active siblings. The target IP shows no open services but has been DNSBL-listed on 3 of 8 threat feeds.

---

## TECHNICAL PROFILE

AttributeValue
**IP Address**45.156.87.162/32
**Risk Score**65/100
**ASN**197170
**Organization**mnt-nl-skylink2-1 / TechTies-Inc
**Network Block**45.156.87.0/24
**Geolocation**NL (Netherlands), Limburg, Eygelshoven
**Timezone**Europe/Amsterdam
**DNSBL Listings**3/8 lists
**Service Status**Firewalled / No Services

---

## THREAT INDICATORS

---

## NEIGHBORHOOD ANALYSIS

The 45.156.87.0/24 subnet contains 36 sibling IPs with the following risk distribution:

Subnet Classification: Mixed abuse profile. Target IP shares network infrastructure with multiple high-risk neighbors, suggesting potential for coordinated abuse or misconfigured infrastructure.

---

## OBSERVATION HISTORY

Recent monitoring indicates:

---

## NETWORK TRAFFIC CHARACTERISTICS

---

## RECOMMENDED ACTIONS

Immediate Actions:

1. Logging Enhancement: Increase logging verbosity for all traffic from this IP

2. Ingress Filtering: Block at perimeter firewall

3. Subnet Monitoring: Monitor adjacent high-risk IPs for correlated activity

Firewall Rules:

```bash

# iptables

iptables -A INPUT -s 45.156.87.162 -j DROP

# nftables

nft add rule inet filter input ip saddr 45.156.87.162 drop

# Cloudflare WAF

ip.src eq 45.156.87.162 → BLOCK

```

---

## ANALYST NOTES

The target IP (45.156.87.162) shows no active services but maintains a moderate risk profile due to subnet-level abuse characteristics. The presence of 4 high-risk neighbors within the same /24 suggests this infrastructure may be misconfigured or shared with malicious actors. Recommend blocking at perimeter level while maintaining observation for pattern correlation. No immediate threat indicators (TOR, spam, known campaigns) detected, but DNSBL listings warrant continued monitoring.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇳🇱 Netherlands
RegionLimburg
CityEygelshoven
TimezoneEurope/Amsterdam
Latitude52.13
Longitude5.29

🏢 Ownership & Registration

Organizationmnt-nl-skylink2-1
ASNAS197170
Network NameTechTies-Inc
CIDR Block45.156.87.0/24
RIRARIN
CountryNL
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRship-behind.vmheaven.io
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesship-behind.vmheaven.io

🔐 DNS Hygiene

Hygiene Score40% (Fair)
SPF3/3 domains
DMARC2/3 domains
FCrDNSNot verified
DNSSECNot signed
CAANot configured
Domains Checked3 domains

☁️ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierUnknown — Insufficient routing data to classify
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
80httptcp—
443httpstcp—
22sshtcpBanner detected
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
Server—
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS197170
Network Prefix45.156.87.0/24
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
23
routing
8%
11
services
17%
24
ownership
17%
23
reputation
28%
17
geolocation
23%
23
Overall20%1021
Coverage: 4/6 dimensions · Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

📅 Observation Timeline 🔄 Live

First Seen2026-07-03 16:58:24 UTC
Last Seen2026-09-29 20:39:29 UTC
Profile Built2026-09-29 21:14:28 UTC
Data FreshnessLive
Signal Types23
Total Observations55
🔍 23 signal types · 55 observations collected
This report is generated from 23+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 45.156.87.162

Who owns the IP address 45.156.87.162?

45.156.87.162 is registered to mnt-nl-skylink2-1. The address falls within the 45.156.87.0/24 network block. Registration is held at ARIN.

Where is 45.156.87.162 located?

Geolocation data places 45.156.87.162 in Eygelshoven, Limburg, Netherlands. The local time zone is Europe/Amsterdam. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 45.156.87.162 malicious or safe?

45.156.87.162 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.

What is the hostname for 45.156.87.162?

The reverse DNS (PTR) record for 45.156.87.162 is ship-behind.vmheaven.io. This hostname is not forward-confirmed, so it should be treated as a weak signal.

What ports are open on 45.156.87.162?

Responsive ports observed on 45.156.87.162 include 80, 443, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.

🏘️ Related IP Addresses

Nearby addresses in 45.156.87.0/24

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.