# THREAT INTELLIGENCE BRIEFING
## IP Address: 45.207.195.95/32
Date: 2026-07-28
Classification: LOW RISK
---
EXECUTIVE SUMMARY
IP address 45.207.195.95 presents a low-risk profile with a risk score of 25. The address is assigned to Cloud Innovation Support (ASN 401701) within the 45.207.195.0/24 subnet. No active malicious indicators or threat campaigns were detected. The IP exhibits characteristics consistent with legitimate multi-service hosting infrastructure.
---
OWNERSHIP AND REGISTRATION
| Field | Value |
|---|---|
| **Organization** | Cloud Innovation Support |
| **ASN** | 401701 |
| **CIDR Block** | 45.207.195.0 - 45.207.195.255 |
| **RIR** | ARIN |
| **Country** | Hong Kong (HK) |
| **Coordinates** | 22.4°N, 114.11°E |
---
NETWORK CLASSIFICATION
| Classification | Status |
|---|---|
| Multi-Service Host | Yes |
| Cloud Infrastructure | No |
| CDN | No |
| VPN/Proxy | No |
| Tor Exit Node | No |
| Hosting Service | No |
| Residential IP | No |
| Bogon | No |
---
THREAT INDICATOR ASSESSMENT
| Indicator | Status |
|---|---|
| Known Attacker | No |
| Spam Source | No |
| Tor Exit Node | No |
| Blacklist Count | 0 |
| DNSBL Listed | 1 of 8 lists |
| Known Campaigns | None |
| Risk Score | 25 (Low) |
---
OPEN SERVICES AND PORTS
| Port | Protocol | Service | Banner |
|---|---|---|---|
| 80 | TCP | HTTP | - |
| 22 | TCP | SSH | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.16 |
| - | - | HTTP Server | nginx |
---
DNS AND EMAIL REPUTATION
| Metric | Value |
|---|---|
| PTR Hostnames | None |
| Forward Resolution | Not confirmed |
| Hosted Domains | 0 |
| SPF Record | Absent |
| DMARC Record | Absent |
| TXT Records | 0 |
---
SUBNET ANALYSIS (45.207.195.0/24)
| Metric | Value |
|---|---|
| Neighbor Count | 0 |
| Abuse Density | 0% |
| High-Risk Neighbors | 0 |
| Medium-Risk Neighbors | 0 |
| Low-Risk Neighbors | 0 |
---
OBSERVATION HISTORY
Total Observations: 14
Geolocation Consistency: Hong Kong (consistent)
Classification Trend: Clean
Threat Persistence: 0 days
Ownership Changes: 0
Recent signals indicate stable infrastructure with no escalation in threat activity. The subnet maintains a clean classification with zero inherited risk from neighboring addresses.
---
RELATIONSHIP GRAPH
External Links: None
- No associated hostnames detected
- No organization certificates
- No related IP clusters
- Network-only relationships (45.207.195.0/24)
---
CONTROL PLANE DATA
| Metric | Value |
|---|---|
| Origin ASN | 401701 |
| BGP Prefix | 45.207.192.0/22 |
| Route Stability | Unstable |
| DNSSEC Valid | Yes |
| Operator Score | 0.1304 (Minimal) |
| Route Changes (30d) | 0 |
---
RECOMMENDED ACTIONS
Firewall Rules: None required
Risk-Based Actions: Monitor only
Threat Status: No immediate action required
---
ANALYST NOTES
The IP address 45.207.195.95 represents standard hosting infrastructure with minimal risk indicators. The single DNSBL listing represents negligible threat. No firewall blocking is recommended at this time. However, SOC teams should monitor for any changes in threat indicators, particularly if the IP begins appearing in spam reports or malware distribution campaigns.
Recommendation: Allow traffic but maintain logging for baseline activity monitoring.
---
*End of Intelligence Briefing*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Cloud Innovation Support |
| ASN | AS401701 |
| Network Name | 45.207.195.0 - 45.207.195.255 |
| CIDR Block | 45.207.195.0/24 |
| RIR | ARIN |
| Country | HK |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Multi-Service Host |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 443, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS401701 |
| Network Prefix | 45.207.192.0/22 |
| Route mapping | Found |
| HSTS | Not detected |
| CSP | Not detected |
| HTTP/2 | Not detected |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-17 17:13:05 UTC |
| Last Seen | 2026-08-31 16:29:26 UTC |
| Profile Built | 2026-08-29 16:39:17 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 20 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 45.207.195.95
Who owns the IP address 45.207.195.95?
45.207.195.95 is registered to Cloud Innovation Support. The address falls within the 45.207.195.0/24 network block. Registration is held at ARIN.
Where is 45.207.195.95 located?
Geolocation data places 45.207.195.95 in Hong Kong, HK, Hong Kong. The local time zone is Asia/Hong_Kong. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 45.207.195.95 malicious or safe?
45.207.195.95 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 45.207.195.95?
Responsive ports observed on 45.207.195.95 include 80, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.