# IP Intelligence Briefing: 45.165.13.108/32
## Executive Summary
IP address 45.165.13.108 presents a moderate risk profile (55/100) with no active threat indicators. The asset is geographically inconsistent and listed on three DNSBLs with high severity ratings. Despite showing elevated risk, the IP lacks established malicious campaigns or known attacker associations.
---
## Ownership & Infrastructure
- ASN: 268663 (R G DE SOUSA LTDA)
- Network Block: 45.165.12.0/22 (CIDR: 346702)
- Geolocation: United States (New York) — *Note: Geographic data conflicts observed*
- Classification: Firewalled / No Services
- RIR: ARIN
---
## Risk Assessment
- Overall Risk Score: 55/100 (Moderate Risk)
- Provider Authority Score: 0 (No provider designation)
- DNSBL Listings: 3 out of 8 total lists (High severity)
- Operator Score: 0.1304 (Minimal)
- Known Threat Indicators: None
- Campaign Associations: None detected
- Tor/Proxy/VPN Status: Not identified
---
## Temporal Analysis
- Observation History: 11 recorded signals
- Geographic Inconsistency: Conflicting location data observed:
- US (confidence: 0.95)
- Brazil, Chapadinha, Maranhão (confidence: 0.70)
- Ownership Stability: No ownership changes recorded
- Threat Persistence: 0 days (No persistent malicious activity)
- Route Stability: Unstable (isRouteStable: false)
- Threat Observation Count: 0
---
## Network Context
- Subnet Abuse Density: 0.0
- Neighbor Analysis: 0 adjacent IPs in /24 subnet
- Related Entities: 1 (Same Network: 346702)
- Campaign Correlations: 0 correlated IPs
- Honeypot Hits: 0
- Enumeration Strikes: 0
---
## Recommended Actions
Immediate
1. Increase logging verbosity for traffic from this IP
2. Review recent activity patterns for anomalies
Firewall/Blocking Recommendations
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 45.165.13.108 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 45.165.13.108 drop` |
| nginx | `deny 45.165.13.108;` |
| pfSense | `45.165.13.108/32` |
| Cloudflare WAF | Block with expression: `ip.src eq 45.165.13.108` |
| AWS WAF | Add address: `45.165.13.108/32` |
---
## Intelligence Narrative
This IP address demonstrates moderate risk characteristics without active malicious indicators. The geographic inconsistency (US vs Brazil reporting) warrants investigation, as it may indicate proxy usage or spoofing. Three DNSBL listings with high severity ratings suggest historical abuse or association with malicious infrastructure. However, the absence of threat indicators, campaigns, and the firewalled state with no open services limit immediate threat. The isolated subnet (0 neighbors, 0 abuse density) suggests this is not part of a larger malicious infrastructure cluster.
Threat Level: LOW-MODERATE
Recommended Handling: Monitor with increased logging; consider blocking if traffic patterns indicate abuse.
---
*Report generated: [Current Date]*
*Data Source: IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | R G DE SOUSA LTDA |
| ASN | AS268663 |
| Network Name | 346702 |
| CIDR Block | 45.165.12.0/22 |
| RIR | ARIN |
| Country | BR |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS268663 |
| Network Prefix | 45.165.12.0/23 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 8% | 2 | 2 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-03 10:49:28 UTC |
| Last Seen | 2026-08-28 00:45:37 UTC |
| Profile Built | 2026-08-29 03:30:07 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 21 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 45.165.13.108
Who owns the IP address 45.165.13.108?
45.165.13.108 is registered to R G DE SOUSA LTDA. The address falls within the 45.165.12.0/22 network block. Registration is held at ARIN.
Where is 45.165.13.108 located?
Geolocation data places 45.165.13.108 in New York, US-NY, United States. The local time zone is America/New_York. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 45.165.13.108 malicious or safe?
45.165.13.108 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.