# IP Intelligence Briefing: 45.55.189.219
Classification: Cloud Infrastructure / Web Server
Date: 2026-08-05
Risk Score: 40 (Moderate Risk)
Status: Monitor
---
## Executive Summary
IP 45.55.189.219 is a DigitalOcean cloud compute instance hosting the domain theodorennelson.com. The IP presents moderate risk (40) primarily due to DNSBL listings, but lacks active threat indicators. Neighborhood analysis indicates a clean subnet with no abuse density. SOC analysts should monitor for route instability but no immediate blocking is warranted absent additional malicious activity.
---
## Infrastructure Profile
Ownership & Network:
- Provider: DigitalOcean, LLC (ASN: 14061)
- CIDR: 45.55.0.0/16 (DIGITALOCEAN-45-55-0-0)
- Location: Clifton, New Jersey, US
- Registration: ARIN
Network Role:
- Infrastructure Type: Cloud Compute
- Service Purpose: Web Server
- Hosting: Yes
- Anycast: No
DNS Resolution:
- Primary Hostname: theodorennelson.com
- Forward Resolution: Confirmed
- PTR Record: theodorennelson.com
- DNSSEC: Valid
---
## Threat Indicators
Current Threat Status: None
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Blacklist Count: 0 active threat feeds
- Abuse Confidence Score: Not applicable
- Campaign Association: None
DNSBL Status:
- Listed on 2 of 8 DNSBLs
- Requires investigation for context
---
## Service Exposure
Open Ports:
| Port | Protocol | Service |
|---|---|---|
| 80 | TCP | HTTP |
| 443 | TCP | HTTPS |
| 22 | TCP | SSH |
Web Server Fingerprint:
- Server: Apache/2.4.58 (Ubuntu)
- SSL/TLS: Let's Encrypt certificate (CN=theodorennelson.com)
- HTTP Version: 1.1
- Status Code: 200
---
## Neighborhood Analysis
Subnet: 45.55.189.0/24
- Abuse Density: 0
- Classification: Clean
- Active Threat Siblings: 0
- Total Siblings: 1
- Inherited Risk: 0
The IP operates in a clean subnet with no adjacent malicious infrastructure.
---
## Relationship Graph
Associated Entities:
- DNS Hostnames: theodorennelson.com (multiple associations)
- Network: DIGITALOCEAN-45-55-0-0 (13 relationship entries)
- No organization-level or certificate-level correlations identified
---
## Historical Observations
Observation Count: 22 total signals
Recent Activity:
- 2026-08-05: Basic signal observations (confidence: 0.60)
- 2026-08-02: HTTP service fingerprinting (confidence: 0.85)
- 2026-07-30: Campaign and ownership signals (confidence: 0.85)
Temporal Analysis:
- Ownership Changes: 0
- Threat Persistence Days: 0
- Threat Observation Count: 0
- Persistently Malicious: No
The IP has been consistently observed without escalation in threat profile.
---
## Control Plane
- Origin ASN: 14061 (DigitalOcean)
- BGP Prefix: 45.55.128.0/18
- Route Stability: Unstable (isRouteStable: false)
- Route Changes (30d): 0
- RPKI State: Not applicable
- DNSSEC Validation: Valid
Route instability warrants periodic verification but does not indicate malicious behavior.
---
## Recommended Security Actions
Assessment: No immediate action required. The IP shows moderate risk primarily from DNSBL listings without confirmed malicious activity.
Recommended Monitoring:
- Monitor for changes in DNSBL status
- Track route stability improvements
- Observe for new threat indicators
Firewall Rules (if blocking required):
```bash
# iptables
iptables -A INPUT -s 45.55.189.219 -j DROP
# nftables
nft add rule inet filter input ip saddr 45.55.189.219 drop
# nginx
deny 45.55.189.219;
```
Cloud Provider Integration:
- Cloudflare WAF: Block with expression `ip.src eq 45.55.189.219`
- AWS WAF: Add address `45.55.189.219/32`
---
## Intelligence Summary
IP 45.55.189.219 operates as a legitimate cloud web server with no active threat indicators. The moderate risk score stems from minor DNSBL associations rather than confirmed malicious activity. No correlation to known attack campaigns or attacker infrastructure was identified. SOC teams should continue monitoring for route stability improvements and DNSBL status changes while maintaining normal observation protocols.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DigitalOcean, LLC |
| ASN | AS14061 |
| Network Name | DIGITALOCEAN-45-55-0-0 |
| CIDR Block | 45.55.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | theodorennelson.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | theodorennelson.com |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | Apache/2.4.58 (Ubuntu) |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18 |
π TLS Certificate
| SANs | theodorennelson.comwww.theodorennelson.com |
| Valid From | 2026-07-22T12:27:08+00:00 |
| Valid Until | 2026-10-20T12:27:07+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
| Serial Number | 05816B3DC2F5351C9452046AF98DEBBB23C3 |
| Thumbprint | 9B317F0EEA3FCE3F3375A7C748D433947145A69F |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 35% | 2 | 4 |
| ownership | 30% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 27% | 2 | 2 |
| Overall | 28% | 10 | 17 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-26 03:09:10 UTC |
| Last Seen | 2026-08-12 20:17:11 UTC |
| Profile Built | 2026-08-12 20:27:17 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 28 |
Full dossier details are available via our API.