## IP Intelligence Briefing: 45.79.152.168/32
Executive Summary
IP address 45.79.152.168 is a low-risk (25/100) Linode cloud compute instance located in the US. No active threat indicators detected. The IP resolves to a binaryedge.ninja domain with no open services. One neighbor IP in the same /24 subnet shows elevated risk (55/100).
---
Ownership & Infrastructure
- Provider: Linode (ASN 63949)
- Organization: LINODE
- CIDR Block: 45.79.0.0/16
- Classification: CloudCompute / Hosting
- Registration: ARIN
- Status: Active cloud infrastructure
Geolocation & Validation
- Claimed Location: Cedar Knolls, New Jersey, US
- Validation Status: GEOGEOSPHERE VALIDATION FAILED
- RTT Anomaly: Observed 23ms RTT contradicts 5988km distance (minimum expected: 119.8ms)
- Note: Geographic validation failure suggests potential spoofing or routing anomaly
Network Role & Services
- Open Ports: None detected
- TLS/Certificates: None
- DNS Resolution: prod-beryllium-us-east-31.li.binaryedge.ninja
- Forward Resolution: Confirmed
- Service Purpose: Firewalled / No Services
Threat Intelligence
- Risk Score: 25 (Low)
- Threat Indicators: None
- Tor Exit: No
- Known Attacker: No
- Spam Source: No
- Blacklist Count: 0
- DNSBL Listed: 1 list
- Campaign Correlation: None identified
- Persistence: No persistent malicious activity observed
Neighborhood Analysis (45.79.152.0/24)
- Subnet Abuse Density: 0.5% (mostly clean)
- Total Siblings: 2
- Active Siblings: 1
- Threat Siblings: 1
- High-Risk Neighbor: 45.79.152.14 (Risk: 55, Authority: 60)
Observation History
- Total Observations: 21 signals
- Most Recent: 2026-08-06T00:50:17 UTC
- Risk Trend: Stable low-risk classification
- Ownership Changes: None
- Threat Persistence: 0 days
Relationships
- DNS Associations: Multiple associations to binaryedge.ninja hostnames
- Network Relations: Multiple LINODE network associations
- Organizational Relations: None
- Certificate Relations: None
---
SOC Recommendations
1. Monitor Neighbor IP: 45.79.152.14 shows elevated risk (55/100). Investigate for potential lateral threat activity.
2. DNS Anomaly: The binaryedge.ninja hostname warrants review. Verify if this aligns with expected infrastructure.
3. Geolocation Discrepancy: Geographic validation failure may indicate routing spoofing or misconfiguration. Cross-reference with known Linode datacenter locations.
4. Current Action: No immediate blocking recommended. Risk profile is low (25/100) with no active threat indicators.
5. Continued Monitoring: Track subnet abuse density trends for 45.79.152.0/24.
---
Conclusion
This IP represents legitimate cloud infrastructure with no active malicious indicators. The primary concern is the elevated-risk neighbor IP in the same subnet. Standard monitoring procedures are recommended; no immediate blocking action is warranted.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Linode |
| ASN | AS63949 |
| Network Name | LINODE |
| CIDR Block | 45.79.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | prod-beryllium-us-east-31.li.binaryedge.ninja |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | prod-beryllium-us-east-31.li.binaryedge.ninja |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.16 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 21% | 2 | 2 |
| ownership | 30% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 35% | 2 | 4 |
| Overall | 27% | 10 | 17 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-30 11:04:07 UTC |
| Last Seen | 2026-08-13 00:41:59 UTC |
| Profile Built | 2026-08-13 00:55:11 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 24 |
Full dossier details are available via our API.