# IP Intelligence Briefing: 45.207.223.196/32
Classification: Low Risk / No Active Threat Indicators
Report Date: Current Analysis Period
Analysis Source: IPDebrief Intelligence Platform
---
## Executive Summary
The target IP address 45.207.223.196 has been analyzed and classified as low risk. No active threat indicators, blacklist listings, or malicious behavior have been observed. The IP is currently firewalled with no open services detected.
---
## Risk Assessment
Overall Risk Score: 0 (Low Risk)
Provider Score: 0
Authority Score: 0
The IP demonstrates no malicious activity indicators across all monitored threat feeds and blacklist sources. No known attacker campaigns or spam source classifications have been identified.
---
## Network & Infrastructure Profile
Origin ASN: 401701
BGP Prefix: 45.207.222.0/23
Registration: COGNETCLOUD-2 (cognetcloud INC, US)
Routing Status: Route instability detected (isRouteStable: false)
RPKI State: Not validated
IRR Consistency: Not assessed
Control Plane Observations:
- Route changes in last 30 days: 0
- MOAS status: False
- DNSSEC validation: Valid
- DNSBL listings: 0 (out of 8 total checked)
---
## Geolocation Data
Reported Country: United States (US)
Geolocation Consensus: False (inconsistent data sources)
GeoPlausible: True
Distance from Origin: 7,832.3 km
Average RTT: 243ms (minimum possible: 156.6ms)
Note: Geolocation data shows consensus discrepancies across multiple sources. This should be considered when correlating with other threat intelligence.
---
## Service & Port Analysis
Open Ports: None detected
Services: Firewalled / No Services
TLS Certificates: None
HTTP Banner: None
The target IP shows no active service exposure, indicating either proper security hardening or inactive infrastructure.
---
## Threat Indicators
Blacklist Count: 0
Known Attacker: False
Tor Exit Node: False
Spam Source: False
Abuse Confidence Score: Not applicable
No threat feeds have flagged this IP address as malicious.
---
## Neighborhood Analysis (45.207.223.0/24)
Subnet Classification: Not classified
Abuse Density: 0
Total Siblings: 0
Active Siblings: 0
Threat Siblings: 0
The /24 subnet contains no neighboring IPs with observable activity, suggesting isolated infrastructure deployment.
---
## Relationship Graph
Connected Entities: None detected
Associated Domains: None
Related Hostnames: None
The IP shows no detectable relationships to other infrastructure, hostnames, or organizations.
---
## Historical Observations
Total Observations: 10 (as of 2026-07-24)
Threat Observation Count: 0
Ownership Changes: 0
Threat Persistence Days: 0
Recent observations include:
- DNS resolution validated (DNSSEC valid)
- ASN attribution: COGNETCLOUD-2 (cognetcloud INC, US)
- Geolocation data collected (5 probes, geoPlausible: true)
- No PTR record resolution
---
## Recommended Security Actions
Action Level: Monitor / No Immediate Action Required
No specific firewall rules or mitigation actions are recommended at this time due to the low-risk classification and absence of active threat indicators.
Monitoring Recommendations:
- Continue passive monitoring of routing stability (isRouteStable: false)
- Monitor for any changes in service exposure
- Re-evaluate if the IP begins appearing in threat feeds
---
## SOC Analyst Notes
- Risk Level: LOW - No immediate threat action required
- Investigation Priority: LOW
- Key Observations: Firewalled IP with no services, no blacklist hits, stable ownership but unstable routing
- Action Required: None at this time
---
End of Briefing
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Cloud Innovation Support |
| ASN | AS401701 |
| Network Name | 45.207.223.0 - 45.207.223.255 |
| CIDR Block | 45.207.223.0/24 |
| RIR | ARIN |
| Country | HK |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Multi-Service Host |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 443, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS401701 |
| Network Prefix | 45.207.222.0/23 |
| Route mapping | Found |
| HSTS | Not detected |
| CSP | Not detected |
| HTTP/2 | Not detected |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 4% | 1 | 1 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-07 12:35:42 UTC |
| Last Seen | 2026-09-01 23:54:56 UTC |
| Profile Built | 2026-09-01 23:56:28 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 20 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 45.207.223.196
Who owns the IP address 45.207.223.196?
45.207.223.196 is registered to Cloud Innovation Support. The address falls within the 45.207.223.0/24 network block. Registration is held at ARIN.
Where is 45.207.223.196 located?
Geolocation data places 45.207.223.196 in Hong Kong, HK, Hong Kong. The local time zone is Asia/Hong_Kong. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 45.207.223.196 malicious or safe?
45.207.223.196 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 45.207.223.196?
Responsive ports observed on 45.207.223.196 include 80, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.