# IP Intelligence Briefing: 45.56.104.173/32
Date: Current
Classification: Moderate Risk (Score: 40)
Provider: Linode (AS63949)
Location: United States, New Jersey
## Executive Summary
Target IP 45.56.104.173 is a Linode cloud compute infrastructure address with moderate risk classification. The IP presents minimal active threat indicators but maintains DNSBL listings on 2 of 8 checked lists. Neighborhood analysis indicates a clean subnet classification with zero abuse density. No open ports or active services detected.
## Infrastructure Profile
- Organization: Linode (LINODE)
- CIDR Block: 45.56.64.0/18
- Infrastructure Type: Cloud Compute
- Network Role: Firewalled / No Services
- Geolocation: US, New Jersey (Cedar Knolls)
## Threat Indicators
- Risk Score: 40 (Moderate)
- Blacklist Count: 0
- DNSBL Listed: 2/8 lists
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Campaign Correlation: None detected
## Behavioral Analysis
- Service Status: No open ports detected
- DNS Resolution: No forward resolution confirmed
- Threat Persistence: 0 days
- Ownership Stability: No ownership changes observed
- Historical Observations: 13 signals logged, no persistent malicious behavior
## Neighborhood Context
- Subnet: 45.56.104.0/24
- Abuse Density: 0.0 (Clean)
- Classification: Clean
- Sibling IPs: 2 total, 2 active, 0 threats
- Notable Neighbor: 45.56.104.238 (Risk: 0, Authority: 50)
## Recommended Actions
Based on the moderate risk score (40) and DNSBL presence, consider the following controls:
Firewall Rules:
- iptables: `iptables -A INPUT -s 45.56.104.173 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 45.56.104.173 drop`
- nginx: `deny 45.56.104.173;`
- Cloudflare WAF: Block with expression `ip.src eq 45.56.104.173`
- AWS WAF: Add 45.56.104.173/32 to block list
## Intelligence Assessment
The IP's moderate risk score appears driven by DNSBL presence rather than active threat activity. The "firewalled/no services" classification suggests this is either a dormant, reserved, or misconfigured cloud address. The clean neighborhood profile (abuse density: 0) indicates the risk is isolated to this specific endpoint rather than representing broader subnet compromise.
SOC Recommendation: Monitor for service activation. If the IP begins showing open ports or traffic patterns, reassess threat level. No immediate blocking required if organizational policy permits cloud provider IPs with moderate risk scores, but firewall rules provided for conservative posture.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Linode |
| ASN | AS63949 |
| Network Name | LINODE |
| CIDR Block | 45.56.64.0/18 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 17% | 1 | 1 |
| Overall | 24% | 9 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-08-02 17:02:38 UTC |
| Last Seen | 2026-08-13 04:05:04 UTC |
| Profile Built | 2026-08-13 04:16:17 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 20 |
Full dossier details are available via our API.