IPDebrief

45.76.59.175

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# THREAT INTELLIGENCE BRIEFING

IP Address: 45.76.59.175/32

Classification: Cloud Infrastructure (Vultr Holdings, LLC)

Risk Assessment: Low Risk (Score: 25/100)

Date: Current Intelligence Cycle

---

## EXECUTIVE SUMMARY

IP 45.76.59.175 is a cloud-hosted server (Vultr) operating as a web service with standard web infrastructure (HTTP/HTTPS, SSH). The IP demonstrates low overall risk but exhibits elevated operator-level signals and has been observed on eight DNS blacklist feeds, including one high-severity listing. No active threat campaigns or known attacker associations detected.

---

## OWNERSHIP & INFRASTRUCTURE

AttributeValue
**Provider**Vultr Holdings, LLC (ASN 20473)
**Infrastructure Type**Cloud Compute
**Location**Dallas, TX, US (ARIN)
**BGP Prefix**45.76.56.0/22
**Route Stability**Stable (no changes in 30 days)
**DNSSEC**Valid

---

## NETWORK SERVICES & CONFIGURATION

Open Ports:

Web Server Details:

TLS Certificate:

DNS Configuration:

---

## THREAT OBSERVATION HISTORY

Total Observations: 24

Recent Activity: 2026-06-20

Key Observations:

Temporal Analysis:

---

## NETWORK RELATIONSHIPS

Connected Entities: 36 relationships identified

---

## SUBNET ANALYSIS

Subnet: 45.76.59.175/24

Abuse Density: 0 (mostly clean)

Threat Siblings: 1

Active Siblings: 0

The /24 subnet shows minimal abuse activity, with this IP representing a single threat sibling.

---

## GEOLOCATION VALIDATION

Flagged Issues:

---

## SECURITY ACTIONS & RECOMMENDATIONS

Current Risk Posture:

Recommended Actions:

1. Monitor TLS certificate validity and expiration

2. Review DNS blacklist listings for source identification

3. Verify geolocation accuracy for traffic analysis

4. Standard firewall rules apply (allow 80/443, restrict 22)

No immediate blocking action recommended based on current risk profile.

---

## INTELLIGENCE CONCLUSION

IP 45.76.59.175 represents legitimate cloud infrastructure hosting services for sabrosanousa.com. While the risk score remains low (25/100), the presence on multiple DNS blacklists warrants continued monitoring. The IP's configuration aligns with standard web hosting practices, and no active malicious behavior or threat campaign associations have been identified.

Classification: LOW RISK - MONITOR

Confidence Level: HIGH (24 observations, 36 relationships)

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionTX
CityDallas
Timezoneβ€”
Latitude32.79
Longitude-96.80

🏒 Ownership & Registration

OrganizationVultr Holdings, LLC
ASNAS20473
Network Nameβ€”
CIDR Block45.76.56.0/22
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR45.76.59.175.vultrusercontent.com
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnames45.76.59.175.vultrusercontent.com

πŸ” DNS Hygiene

Hygiene Score60% (Good)
SPFPresent
DMARCPresent
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeWeb Server
Network TierHosting β€” Infrastructure provider without advanced routing
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpβ€”
443httpstcpβ€”
22sshtcp
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
ServerApache/2.4.6 (CentOS) OpenSSL/1.0.2k-fips PHP/7.0.31
HTTP Titleβ€”
SSH VersionSSH-2.0-OpenSSH_7.4

πŸ” TLS Certificate

πŸ”’
CN=*.sabrosanousa.com
Issued by CN=Sectigo Public Server Authentication CA DV R36, O=Sectigo Limited, C=GB
Self-signed: No
SANs*.sabrosanousa.comsabrosanousa.com
Valid From2025-08-29T00:00:00+00:00
Valid Until2026-09-29T23:59:59+00:00
TLS ProtocolTls12
Cipher SuiteTLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period396 days
Serial Number252CD8478ED7CC0497876A786BC404AC
ThumbprintAC01D529A5B225EDFA682C5351704625E3ED3551

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
33%
24
routing
24%
23
services
28%
23
ownership
27%
34
reputation
30%
13
geolocation
31%
23
Overall29%1220
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-18 15:26:59 UTC
Last Seen2026-06-28 07:39:26 UTC
Profile Built2026-06-29 07:47:25 UTC
Data FreshnessLive
Signal Types27
Total Observations31
πŸ” 27 signal types Β· 31 observations collected
This report is generated from 27+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.