IP Intelligence Briefing: 45.165.14.197
*Generated via IPDebrief Analysis*
---
**Core Profile**
- Risk Score: 50 (Moderate Risk)
- Ownership: R G DE SOUSA LTDA (AS268663), Brazil (ARIN)
- Geolocation: Chapadinha, Maranhão, Brazil (inferred via 2 geo sources, 2500km accuracy radius)
- Network Role: Web server (HTTPS, SSH, HTTP-alt services)
- Threat Indicators: No active threats, abuse confidence score null, no blacklist entries.
---
**Key Observations**
1. Services & TLS:
- Hosts Apache HTTP server with self-signed TLS certificate (subject/issuer: 192.168.15.59).
- Open ports: 443 (HTTPS), 22 (SSH), 8080 (HTTP-alt), 8443 (HTTPS-alt).
- No malicious banners or campaign correlations detected.
2. DNS & Network:
- No PTR records or domain associations.
- BGP prefix: 45.165.14.0/24 (AS268663), classified as "mostly_clean" with 1 abuse-reported sibling.
- DNSSEC valid, CAA records present, but 2 DNSBL listings (high-risk lists).
3. Historical Activity:
- Last observed June 15, 2026 (Apache HTTP 200 OK).
- BGP prefix registered October 23, 2018 (ARIN).
- Geolocation inferred via 3 sources (latitude -14.24, longitude -51.93).
---
**Relationships & Neighborhood**
- Network Links: 41 inferred relationships (all tied to AS268663/346702).
- Subnet Analysis: 45.165.14.0/24 subnet has 1 abuse-reported IP; 0 active malicious neighbors.
- Operator Risk: "Minimal" (0.2174 score), no recent ownership changes.
---
**Threat Context**
- No Active Malicious Indicators: No malware, phishing, or exploit activity detected.
- DNSBL Flags: 2 DNSBL listings (potential spam or malicious activity).
- Self-Signed Certificate: May indicate internal/development server, but requires validation.
---
**Recommended Actions**
1. Monitor DNSBL Listings: Investigate why this IP is listed on 2 DNSBLs (e.g., spam, phishing).
2. Verify TLS Certificate: Confirm if the self-signed certificate is intentional (internal use) or a misconfiguration.
3. Network Segmentation: Ensure this subnet (45.165.14.0/24) is isolated from critical assets due to 1 abuse-reported neighbor.
4. Geolocation Validation: Cross-check IP's location with internal user databases to confirm legitimacy.
---
*End of Briefing*
*Generated by IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | R G DE SOUSA LTDA |
| ASN | AS268663 |
| Network Name | 346702 |
| CIDR Block | 45.165.12.0/22 |
| RIR | ARIN |
| Country | BR |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| 8080 | http-alt | tcp | โ |
| 8443 | https-alt | tcp | โ |
| Closed Ports | 25, 80, 3389 (4 open / 7 scanned) | ||
| Server | Apache |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_7.6p1 Ubuntu-4ubuntu0.7 |
๐ TLS Certificate
CN=192.168.15.59, OU=IT Department, O=Global Security, L=SaoPaulo, S=SaoPaulo, C=BR was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.| SANs | None |
| Valid From | 2022-05-31T21:54:39+00:00 |
| Valid Until | 2023-05-31T21:54:39+00:00 (expired) |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 365 days |
| Serial Number | 6C2EBFD7473EB2767134FF7627A52C00CF619A0A |
| Thumbprint | B9818FF0E7ACEA3A88B405C974D1DF09B91AC577 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 30% | 2 | 4 |
| ownership | 19% | 2 | 2 |
| reputation | 22% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 22% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-13 12:13:25 UTC |
| Last Seen | 2026-06-26 18:11:20 UTC |
| Profile Built | 2026-06-24 16:03:05 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.