IPDebrief

45.56.72.249

IP Intelligence Dossier
Your IP: 216.73.217.34
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 45.56.72.249/32

Classification: Moderate Risk | Date: 2026-08-13

Analyst: IPDebrief Intelligence Team

---

## Executive Summary

IP 45.56.72.249 resolved to Linode infrastructure with a moderate risk score (50/100). The address is hosted in Richardson, Texas, with no active open ports or services detected. While the IP shows no confirmed malicious indicators, it appears on 2 of 8 threat intelligence feeds and demonstrates moderate neighborhood abuse density (0.5).

---

## Technical Profile

AttributeValue
**IP Address**45.56.72.249
**ASN**63949 (Linode LLC)
**Organization**Linode
**CIDR Block**45.56.64.0/18
**Location**Richardson, TX, United States
**Reputation**Moderate Risk
**Risk Score**50
**DNS Record**45-56-72-249.ip.linodeusercontent.com
**Network Role**Hosting Provider

---

## Threat Indicators

---

## Network Context

The /24 neighborhood (45.56.72.0/24) shows moderate abuse density with one active sibling IP (45.56.72.142) rated at risk score 20. The target IP itself was classified as "mostly_clean" with an inherited risk score of 2. No other high-risk neighbors were detected.

---

## Historical Analysis

Observation history indicates 20 data points collected. The IP demonstrated 1 threat observation event with no persistent malicious behavior. Ownership remains stable with no changes recorded. Geographic validation flagged a discrepancy between reported coordinates (Richardson, TX) and probe data suggesting a 7,978 km distance violation, though this may indicate routing anomalies rather than actual location misreporting.

---

## Recommended Actions

Based on the risk profile, the following defensive measures are recommended:

Firewall Rules:

Application-Level Blocking:

Cloud Platforms:

---

## Assessment

IP 45.56.72.249 presents a moderate-risk profile consistent with cloud hosting infrastructure. While no active attack signatures were detected, the presence on threat feeds and moderate neighborhood abuse density warrant defensive blocking. The IP should be monitored for escalation in threat activity or correlation with known campaigns.

Recommended Action: Apply blocking rules with continued monitoring.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionTX
CityRichardson
TimezoneAmerica/Chicago
Latitude31.97
Longitude-99.90

🏒 Ownership & Registration

OrganizationLinode
ASNAS63949
Network NameLINODE
CIDR Block45.56.64.0/18
RIRARIN
CountryUnited States
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR45-56-72-249.ip.linodeusercontent.com
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnames45-56-72-249.ip.linodeusercontent.com

πŸ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierTier 3 β€” Basic operator with some routing infrastructure
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
38%
25
routing
13%
11
services
19%
22
ownership
27%
23
reputation
22%
13
geolocation
27%
23
Overall24%1017
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) β€” 1 contradiction(s)
AttributionModerate (55%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Claimed geolocation contradicts RTT physics measurement

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-08-13 06:45:02 UTC
Last Seen2026-08-22 18:11:59 UTC
Profile Built2026-08-29 10:18:14 UTC
Data FreshnessLive
Signal Types24
Total Observations26
πŸ” 24 signal types Β· 26 observations collected
This report is generated from 24+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.