# IPDEBRIEF INTELLIGENCE BRIEFING
Target IP: 45.162.20.49/32
Classification: High Risk
Date: 2026-07-31
## EXECUTIVE SUMMARY
IP 45.162.20.49 is a high-risk (score: 80/100) endpoint located in Cabildo, Buenos Aires, Argentina, operated by ELDA SALERNO (FULLNET) under ASN 267690. The address is listed on 5 DNS blacklists and exhibits single-service hosting behavior with HTTP exposure on port 80. Neighborhood analysis indicates moderate abuse density (5%) within the /24 subnet.
## OWNERSHIP AND INFRASTRUCTURE
- ASN: 267690 (ELDA SALERNO/FULLNET)
- CIDR Block: 45.162.20.0/23 (45.162.20.0 - 45.162.21.255)
- Country: Argentina (AR)
- Region: Buenos Aires
- City: Cabildo
- Service Classification: Single-Service Host
- BGP Prefix: 45.162.20.0/23 (Origin ASN 267690)
- Route Stability: Unstable (isRouteStable: false)
- DNSSEC: Valid
## NETWORK SERVICES
- Open Ports: TCP/80 (HTTP)
- TLS Certificate: None
- PTR Hostnames: None
- Forward Resolution: None confirmed
- Email Authentication: SPF: Not configured, DMARC: Not configured
## THREAT PROFILE
- Risk Score: 80 (High)
- Abuse Confidence Score: Not available
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- DNSBL Listings: 5 of 8 total lists
- Operator Score: 0.1304 (Minimal)
- Threat Feeds: None detected
- Known Campaigns: None correlated
- Threat Persistence: 0 days (not persistently malicious)
## OBSERVATION HISTORY
Fourteen observations recorded. Most recent activity dated 2026-07-31. Key signals include:
- Geolocation inference consistent with Argentina (confidence: 52%)
- Connection failures observed during HTTP probing
- No ownership changes recorded
- No persistent malicious behavior detected over observation period
## SUBNET ANALYSIS
/24 Neighborhood: 45.162.20.0/24
- Total Neighbors: 100
- Abuse Density: 0.05 (5%)
- Risk Distribution:
- High Risk: 5 IPs
- Medium Risk: 83 IPs
- Low Risk: 11 IPs
Notable High-Risk Neighbors:
- 45.162.20.5 (Risk: 55)
- 45.162.20.11 (Risk: 55)
## RELATIONSHIP ANALYSIS
Relationship graph shows only internal network relationships (same network block 45.162.20.0 - 45.162.21.255). No external associations detected:
- Hostnames: None
- Organizations: None beyond ownership record
- Certificates: None
- Correlated IPs: None
## RECOMMENDED ACTIONS
Based on the risk profile and threat indicators:
1. Firewall Rules: Consider blocking or rate-limiting traffic to/from 45.162.20.0/23
2. Monitoring: Enable enhanced logging for connections to port 80
3. DNS Filtering: Apply block rules for the 5 DNSBL entries
4. Subnet Assessment: Evaluate 45.162.20.5 and 45.162.20.11 for potential related threat activity
5. Email Security: No SPF/DMARC records detected; verify sender authenticity if mail relay suspected
## INTELLIGENCE ASSESSMENT
The endpoint presents elevated risk primarily due to DNSBL presence and high-risk classification. While not confirmed as an active attacker, the combination of blacklistings and neighborhood abuse density warrants defensive monitoring. The /23 network appears to be a commercial hosting provider with mixed-risk profile. No evidence of active malicious campaigns or persistent threats at this address.
Threat Level: Elevated
Priority: Medium
Recommended Action: Monitor and consider blocking based on organizational risk tolerance
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | ELDA SALERNO(FULLNET) |
| ASN | AS267690 |
| Network Name | 45.162.20.0 - 45.162.21.255 |
| CIDR Block | 45.162.20.0/23 |
| RIR | ARIN |
| Country | AR |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| Closed Ports | 22, 25, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 35% | 2 | 2 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 18% | 5 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-30 11:04:05 UTC |
| Last Seen | 2026-08-09 10:51:32 UTC |
| Profile Built | 2026-08-08 17:05:20 UTC |
| Data Freshness | Live |
| Signal Types | 15 |
| Total Observations | 16 |
Full dossier details are available via our API.