# IP Intelligence Briefing: 45.56.94.223/32
Classification: LOW RISK
Report Date: 2026-08-05
---
## Executive Summary
IP 45.56.94.223 is a low-risk residential IP address hosted on Linode cloud infrastructure. The IP shows minimal threat indicators with a risk score of 25. No active malicious campaigns, known attacker status, or spam source designation detected. The address operates as a web server with HTTPS services only.
---
## Network Profile
| Attribute | Value |
|---|---|
| **Organization** | Linode (ASN 63949) |
| **CIDR Block** | 45.56.64.0/18 |
| **Geolocation** | Fremont, California, US |
| **Network Type** | CloudCompute / Hosting |
| **Risk Score** | 25 (Low Risk) |
| **Blacklist Count** | 0 |
---
## Technical Observations
Open Services:
- Port 443/TCP (HTTPS)
- TLS Certificate: Issued by AnchorFree Security Operations (CN=a620e6777f64, OU=AnchorFree Security Operations, O=AnchorFree)
DNS Status:
- No PTR hostnames resolved
- Forward resolution not confirmed
- No SPF or DMARC records
Control Plane:
- DNSBL listed on 1 of 8 total lists
- BGP prefix: 45.56.80.0/20
- Route stability: False
---
## Threat Intelligence
Current Threat Status:
- IsTorExit: False
- IsKnownAttacker: False
- IsSpamSource: False
- Threat Feeds: None detected
- Known Campaigns: None
Abuse Indicators:
- Abuse Confidence Score: Not applicable (low threat)
- Pulsedive Risk: Not reported
- Campaign Likelihood: None
---
## Neighborhood Analysis
Subnet: 45.56.94.223/24
- Abuse Density: 1 (mostly_clean classification)
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 1
---
## Historical Signals
Observation count: 20 signals recorded. Recent activity observed on 2026-08-05:
| Signal Type | Observation Date | Confidence |
|---|---|---|
| Ownership/Threat Data | 2026-08-05 17:59:42 | 0.85 |
| Subnet Analysis | 2026-08-05 17:58:33 | 0.40 |
| BGP Prefix | 2026-08-05 17:56:51 | 0.20 |
| Geolocation | 2026-08-05 17:56:34 | 0.35 |
| ICMP/Validation | 2026-08-05 17:56:07 | 0.50 |
Threat Persistence: 0 days. Not classified as persistently malicious.
---
## Network Relationships
Multiple network-level relationships identified pointing to Linode infrastructure. No anomalous cross-network associations detected.
---
## SOC Recommendations
Priority: LOW
1. No immediate action required β IP classified as low risk with minimal abuse indicators
2. Monitor for changes β Track for any escalation in threat indicators or blacklist additions
3. Contextual awareness β While Linode hosting is generally legitimate, verify against known threat feeds if connection attempts originate from this IP
4. False positive potential β AnchorFree certificate issuer is commonly used for legitimate services; no certificate-based threats identified
Actionable Rule (Optional):
```
# No block recommended β low risk profile
# Consider logging for visibility if traffic originates from this IP
```
---
Analyst Notes: This IP represents standard Linode cloud hosting infrastructure. The single DNSBL listing shows minimal abuse activity. Historical data indicates stable ownership with no persistent malicious behavior. Suitable for routine monitoring without immediate blocking or investigation.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Linode |
| ASN | AS63949 |
| Network Name | LINODE |
| CIDR Block | 45.56.64.0/18 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 45-56-94-223.ip.linodeusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 45-56-94-223.ip.linodeusercontent.com |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
CN=a620e6777f64, OU=AnchorFree Security Operations, O=AnchorFree was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.| SANs | None |
| Valid From | 2026-07-26T13:05:14+00:00 |
| Valid Until | 2026-08-01T13:05:14+00:00 (expired) |
| TLS Protocol | Tls12 |
| Cipher Suite | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 6 days |
| Serial Number | 7522A80DD8D13B99FE4BCDFCDC18375CCEC52856 |
| Thumbprint | 0ED7778A672422672D02FE3E3A3A4C0E2EDB3602 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 42% | 2 | 5 |
| routing | 13% | 1 | 1 |
| services | 45% | 2 | 5 |
| ownership | 30% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 32% | 10 | 20 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-23 13:57:09 UTC |
| Last Seen | 2026-08-12 17:47:24 UTC |
| Profile Built | 2026-08-12 18:02:05 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 27 |
Full dossier details are available via our API.