IPDebrief

45.78.199.70

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 45.78.199.70/32

Date: 2026-06-26

Classification: MODERATE RISK

Status: RECOMMENDED FOR BLOCK

---

## Executive Summary

IP address 45.78.199.70 is associated with IRT-BYTEPLUS-SG (ASN 150436) and is located in Singapore. The IP presents a moderate risk profile (risk score: 40/100) with evidence of being firewalled with no open services. The /24 subnet (45.78.199.0/24) exhibits high abuse density at 57.14%, with 12 of 21 sibling IPs classified as threats.

## Technical Profile

AttributeValue
**Risk Score**40 (Moderate)
**ASN**150436
**Organization**IRT-BYTEPLUS-SG
**Location**Singapore (SG)
**CIDR Block**45.78.199.70/24
**Network Role**Firewalled / No Services
**DNSBL Listed**1 of 8 lists
**Is Tor Exit**No
**Is Known Attacker**No

## Neighborhood Analysis

The 45.78.199.0/24 subnet demonstrates elevated abuse characteristics:

Risk distribution across neighboring IPs shows 11 medium-risk and 9 low-risk addresses, with no high-risk neighbors currently identified. This indicates the subnet is shared infrastructure with mixed service profiles.

## Threat Indicators

The IP is not associated with any known malicious campaigns and shows no Tor exit node behavior or spam source classification.

## Behavioral History

Observation history reveals 18 signals captured between 2026-06-05 and 2026-06-26. Key temporal indicators:

## Recommended Security Actions

Based on risk profile analysis, the following blocking rules are recommended:

```bash

# iptables

iptables -A INPUT -s 45.78.199.70 -j DROP

# nftables

nft add rule inet filter input ip saddr 45.78.199.70 drop

# nginx

deny 45.78.199.70;

# pfSense

45.78.199.70/32

# Cloudflare WAF

{

"description": "Block 45.78.199.70 β€” IPDebrief risk score 40",

"action": "block",

"filter": {

"expression": "ip.src eq 45.78.199.70"

}

}

# AWS WAF

{

"Addresses": ["45.78.199.70/32"],

"Description": "IPDebrief risk 40"

}

```

## Analyst Notes

1. Subnet Context: The IP belongs to a subnet with 57.14% abuse density. Consider implementing subnet-level blocking (45.78.199.0/24) if threat correlation warrants.

2. Service Status: No open ports or services detected. The "Firewalled / No Services" classification suggests the IP may be used for outbound traffic only or is behind enterprise firewalling.

3. Geographic Attribution: Singapore-based infrastructure under BYTEPLUS hosting. Verify against known legitimate traffic patterns before blocking.

4. Action Priority: Medium. The moderate risk score (40) combined with subnet-level abuse indicators warrants blocking, but correlation with internal threat intelligence is recommended before enforcement.

---

Source: IPDebrief Intelligence Platform

Data Freshness: Current (2026-06-26)

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΈπŸ‡¬ Singapore
Regionβ€”
CitySingapore
TimezoneAsia/Singapore
Latitude1.35
Longitude103.82

🏒 Ownership & Registration

OrganizationIRT-BYTEPLUS-SG
ASNAS150436
Network Nameβ€”
CIDR Blockβ€”
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)

πŸ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown β€” Insufficient routing data to classify
No specific classification

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
30%
24
routing
13%
11
services
15%
22
ownership
27%
23
reputation
22%
13
geolocation
19%
22
Overall21%1015
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-10 22:17:43 UTC
Last Seen2026-06-26 05:28:13 UTC
Profile Built2026-06-26 05:35:40 UTC
Data FreshnessLive
Signal Types17
Total Observations17
πŸ” 17 signal types Β· 17 observations collected
This report is generated from 17+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.