IPDebrief

45.3.44.45

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 45.3.44.45/32

## Executive Summary

IP address 45.3.44.45 presents a moderate risk profile (50/100) with no confirmed malicious activity but notable DNSBL listings and geolocation inconsistencies. The IP operates as a single-service host within the 45.3.32.0/20 block owned by lir-de-3xktechgmbh-1-MNT.

## Technical Profile

Ownership & Network: ASN 200373, registered to network DE-3XKTECHGMBH-20150902 within the 45.3.32.0/20 block. Registration authority is ARIN.

Geolocation: Conflicting signals observed. Primary consensus indicates Germany (Schorfheide, 51.17°N, 10.45°E), though MaxMind Geolite2 detected Madrid, Spain (40.4153°N, -3.694°E). Geo validation flagged as implausible with 400km accuracy radius.

Network Classification: Single-service host, not classified as cloud, CDN, VPN, proxy, or hosting infrastructure.

Control Plane: BGP prefix 45.3.44.0/24. Route stability flagged as false with zero route changes in 30 days. RPKI state, IRR consistency, and MOAS status unavailable.

## Threat Indicators

Risk Assessment: Moderate risk score of 50. No evidence of known attacker reputation, Tor exit node, or spam source activity.

DNSBL Status: Listed on 2 of 8 queried DNSBLs with zero overall blacklist count.

Threat Feeds: No indicators in Pulsedive or other threat feeds. No known campaign associations.

Abuse Confidence: Not scored due to insufficient threat evidence.

## Service Analysis

Open Ports: Port 22/SSH open with banner indicating "Exceeded MaxStartups" limit.

TLS/HTTP: No TLS certificate detected. HTTP title, server banner, and certificate data unavailable.

DNS Records: No PTR hostnames. Forward DNS resolution not confirmed. Zero hosted domains. No SPF, DMARC, or TXT records present.

## Neighborhood Assessment

Subnet 45.3.44.0/24 contains 8 sibling IPs with abuse density of 0. Risk distribution shows 0 high-risk, 0 medium-risk, and 8 low-risk neighbors (scores 0-25). No inherited risk detected.

## Historical Signals

11 observations recorded as of 2026-07-31. Geo signals showed variation between Germany and Spain sources. Ownership signals consistently identified as lir-de-3xktechgmbh-1-MNT. No persistent malicious behavior detected (0 threat persistence days, 0 threat observation count).

## Relationships

Single relationship detected: same network association with DE-3XKTECHGMBH-20150902 network. No certificates, hostnames, or organizational links beyond network classification.

## Recommended Actions

Blocking rules generated for multiple platforms:

## Analyst Notes

The IP exhibits minimal operator score (0.1304) and DNSSEC validation. SSH port configuration suggests potential brute-force protection attempts. Geolocation inconsistencies warrant monitoring but do not confirm malicious activity. No immediate threat indicators present; however, DNSBL listings warrant periodic re-evaluation.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฉ๐Ÿ‡ช Germany
RegionUS-NY
CityNew York
TimezoneEurope/Berlin
Latitude51.17
Longitude10.45

๐Ÿข Ownership & Registration

Organizationlir-de-3xktechgmbh-1-MNT
ASNAS200373
Network NameDE-3XKTECHGMBH-20150902
CIDR Block45.3.32.0/20
RIRARIN
CountryDE
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)

๐Ÿ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeSingle-Service Host
Network TierUnknown โ€” Insufficient routing data to classify
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
22sshtcp
Closed Ports25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
35%
22
ownership
0%
00
reputation
0%
00
geolocation
0%
00
Overall14%44
Coverage: 3/6 dimensions ยท Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-07-30 11:04:06 UTC
Last Seen2026-08-01 04:25:53 UTC
Profile Built2026-07-31 02:37:55 UTC
Data FreshnessLive
Signal Types14
Total Observations14
๐Ÿ” 14 signal types ยท 14 observations collected
This report is generated from 14+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.