# IP Intelligence Briefing: 45.190.205.171/32
Classification: High Risk (Risk Score: 80/100)
Date: 2026-07-28
Analyst: IPDebrief SOC Intelligence
---
## Executive Summary
IP 45.190.205.171 is classified as High Risk with a score of 80/100. The address belongs to a Brazilian network (AS269630) with geolocation indicators pointing to Orindiúva, São Paulo. While no active threat indicators are currently present, the IP exhibits elevated operator scoring and is listed on 4 out of 8 DNSBLs. The surrounding /24 subnet shows a concerning abuse density of 0.154, with two sibling IPs also flagged as high risk.
---
## Network Ownership & Registration
| Attribute | Value |
|---|---|
| ASN | 269630 |
| Organization | José Carlos Santana Júnior-ME |
| Netname | 375991 |
| CIDR Block | 45.190.204.0/22 |
| RIR | ARIN |
| Registration Date | Not available |
| Abuse Contact | None listed |
Network Role Classification: Firewalled / No Services detected. No open ports, TLS certificates, or HTTP services identified during probing.
---
## Geolocation Intelligence
| Attribute | Value |
|---|---|
| Country | Brazil (BR) |
| Region | São Paulo |
| City | Orindiúva |
| Coordinates | -14.24°, -51.93° |
| Accuracy Radius | 2500km |
| Geo Consensus | True |
| Geo Plausible | False |
Note: Geolocation data shows inconsistency flags (geoPlausible: false) with a large accuracy radius, suggesting potential spoofing or data quality issues. Multiple geolocation sources confirm Brazil/São Paulo origin.
---
## Threat Intelligence Profile
Current Threat Indicators: None actively detected
Abuse Confidence Score: Not available
Known Campaigns: None
Tor Exit Node: No
Known Attacker: No
Spam Source: No
Blacklist Count: 0 (despite DNSBL presence)
Control Plane Assessment:
- Route Stability: Unstable
- Operator Score: 0.1304 (Minimal)
- DNSBL Listed: 4/8 lists
- DNSSEC Valid: Yes
---
## Observation History
Total Observations: 12 signals recorded
Recent Activity: Multiple geolocation and ownership signals observed on 2026-07-28 within 5-minute windows
Signal Timeline:
- 03:49 UTC: Geolocation signal (São Paulo, Brazil) - Confidence: 70%
- 03:51 UTC: Network role confirmation - Confidence: 30%
- 03:54 UTC: Ownership consistency signal - Confidence: 85%
Temporal Indicators:
- Ownership Changes: 0
- Threat Persistence Days: 0
- Persistently Malicious: No
---
## Neighborhood Analysis (/24 Subnet)
Subnet: 45.190.205.0/24
Total Siblings: 13
Abuse Density: 0.154 (Moderate-High)
Risk Distribution:
- High Risk: 2 IPs
- Medium Risk: 7 IPs
- Low Risk: 4 IPs
High-Risk Siblings (Risk Score 80/100):
- 45.190.205.146
- 45.190.205.193
Medium-Risk Siblings (Risk Score 55/100):
- 45.190.205.141
- 45.190.205.191
- 45.190.205.207
- 45.190.205.219
- 45.190.205.251
---
## Recommended Security Actions
Immediate Firewall Rules
iptables:
```
iptables -A INPUT -s 45.190.205.171 -j DROP
```
nftables:
```
nft add rule inet filter input ip saddr 45.190.205.171 drop
```
nginx:
```
deny 45.190.205.171;
```
Cloud Platform Recommendations
Cloudflare WAF:
- Action: Block
- Expression: `ip.src eq 45.190.205.171`
- Description: IPDebrief risk score 80
AWS WAF:
- Addresses: 45.190.205.171/32
- Description: IPDebrief risk 80
pfSense:
- Rule: 45.190.205.171/32 (block)
Monitoring Recommendations
Critical: Increase logging verbosity and review recent activity from this IP due to elevated risk score (80/100).
---
## SOC Analyst Notes
1. Block Decision: Recommend blocking this IP at perimeter firewalls and WAF based on high risk score (80/100) and DNSBL presence.
2. Subnet Correlation: Two additional IPs in the same /24 subnet (45.190.205.146 and 45.190.205.193) show identical high-risk scores. Consider subnet-level blocking if the target IP confirms malicious activity.
3. Geolocation Inconsistency: The geoPlausible flag being false warrants correlation with other indicators. The large 2500km accuracy radius suggests potential spoofing.
4. No Active Services: Despite high risk classification, no open ports or services were detected. This may indicate the IP is being used for scanning/probing activities or is simply inactive.
5. Operator Score: The minimal operator score (0.1304) suggests this IP is not part of a large hosting infrastructure, making it more likely to be associated with opportunistic abuse.
---
Status: Action Required
Confidence: High (80/100 risk score supported by multiple data sources)
Next Review: Monitor for changes in threat indicators or geolocation consistency
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | José Carlos Santana Júnior-ME |
| ASN | AS269630 |
| Network Name | 375991 |
| CIDR Block | 45.190.204.0/22 |
| RIR | ARIN |
| Country | BR |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 443 | https | tcp | — |
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS269630 |
| Network Prefix | 45.190.204.0/23 |
| Route mapping | Found |
| Certificates in transparency logs | 0 certificates |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-16 10:36:48 UTC |
| Last Seen | 2026-09-29 03:08:17 UTC |
| Profile Built | 2026-09-12 09:59:53 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 22 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 45.190.205.171
Who owns the IP address 45.190.205.171?
45.190.205.171 is registered to José Carlos Santana Júnior-ME. The address falls within the 45.190.204.0/22 network block. Registration is held at ARIN.
Where is 45.190.205.171 located?
Geolocation data places 45.190.205.171 in Orindiuva, SP, Brazil. The local time zone is America/Sao_Paulo. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 45.190.205.171 malicious or safe?
45.190.205.171 currently carries a high risk assessment, meaning indicators associated with malicious or abusive activity have been observed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 45.190.205.171?
Responsive ports observed on 45.190.205.171 include 80, 443, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.