# IP Intelligence Briefing: 45.56.119.151/32
Date: 2026-08-12
Status: Moderate Risk
Risk Score: 40
## Executive Summary
IP address 45.56.119.151 belongs to Linode (ASN 63949), a cloud computing provider. The IP is classified as Moderate Risk with a score of 40 and is currently hosted in Atlanta, Georgia, United States. The address is listed on 2 out of 8 DNSBL entries with high severity ratings, though the parent subnet (45.56.119.0/24) shows abuse density of 0 and is classified as mostly clean. No open services were detected; the system appears firewalled with no accessible ports.
## Ownership and Infrastructure
- Provider: Linode
- ASN: 63949
- CIDR Block: 45.56.64.0/18
- Network Role: CloudCompute / Cloud Hosting
- Infrastructure Type: Cloud Infrastructure
- DNS PTR: 45-56-119-151.ip.linodeusercontent.com
- Forward Resolution: Confirmed (1 hostname)
- Reverse DNS: 45-56-119-151.ip.linodeusercontent.com
## Threat Indicators
- Blacklist Count: 2 DNSBL listings
- DNSBL Total Lists: 8
- Abuse Confidence Score: Not available
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Known Campaigns: None detected
- Route Stability: False (route changes observed in 30-day window)
## Historical Observations
The IP has been observed 23 times across multiple signal types. Key findings include:
- Cloud infrastructure classification consistently detected
- DNSBL listings with high severity observed on 2026-08-12
- No persistent malicious activity patterns identified
- Ownership stability maintained with zero ownership changes
- Threat observation count: 1
- Threat persistence days: 0
## Network Neighborhood Analysis
The /24 subnet (45.56.119.151/24) contains:
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 1
- Abuse Density: 0 (mostly clean)
- Inherited Risk: 2
- No additional neighbor IPs detected in the immediate subnet
## Control Plane Analysis
- BGP Prefix: 45.56.112.0/21
- Origin ASN: 63949
- Route Stability: False
- IS Route Stable: False
- Operator Score: 0.2609 (Basic classification)
- RPKI State: Not available
- DNSSEC: Valid
## Recommended Actions
Based on the risk profile, the following blocking rules are recommended:
Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 45.56.119.151 -j DROP
# nftables
nft add rule inet filter input ip saddr 45.56.119.151 drop
# nginx
deny 45.56.119.151;
```
Cloud Platform Blocks:
- Cloudflare WAF: Block with expression `ip.src eq 45.56.119.151`
- AWS WAF: Address: 45.56.119.151/32, Description: "IPDebrief risk 40"
- pfSense: 45.56.119.151/32
## Assessment
The IP presents moderate risk due to DNSBL listings while operating within a cloud hosting environment. The subnet shows low abuse density, suggesting the IP may be compromised or misconfigured rather than part of a coordinated attack. No active services are exposed, limiting potential lateral movement. The lack of persistent malicious behavior and the clean neighborhood profile indicate this is likely an isolated incident. SOC analysts may monitor the IP for continued DNSBL activity while implementing the recommended blocking rules.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Linode |
| ASN | AS63949 |
| Network Name | LINODE |
| CIDR Block | 45.56.64.0/18 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 45-56-119-151.ip.linodeusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 45-56-119-151.ip.linodeusercontent.com |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_10.0p2 Debian-7+deb13u4 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 42% | 2 | 5 |
| routing | 13% | 1 | 1 |
| services | 21% | 2 | 2 |
| ownership | 30% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 17% | 1 | 1 |
| Overall | 25% | 9 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-23 13:57:09 UTC |
| Last Seen | 2026-08-12 17:46:47 UTC |
| Profile Built | 2026-08-12 18:03:11 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 23 |
Full dossier details are available via our API.