# IP Intelligence Briefing: 45.79.190.104/32
Date: Current Analysis
Classification: Moderate Risk
Primary Provider: Linode (ASN 63949)
## Executive Summary
Target IP 45.79.190.104 presents a moderate risk profile (risk score: 65/100) with elevated characteristics requiring monitoring. The address is hosted on Linode infrastructure in Cedar Knolls, NJ, US. No active threat indicators were observed, though the IP appears on three DNSBL entries out of eight total lists checked.
## Technical Profile
Ownership & Classification:
- ASN: 63949 (AKAMAI-LINODE-AP)
- Organization: Linode
- Network: 45.79.128.0/18
- Service Purpose: Single-Service Host/Hosting
- Geolocation: United States (New Jersey)
DNS Resolution:
- PTR: 45-79-190-104.ip.linodeusercontent.com
- Forward resolution: Confirmed
- DNSSEC: Valid
- Email Authentication: SPF and DMARC absent
Network Services:
- Open Ports: 22/TCP (SSH)
- SSH Banner: SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15
- TLS Certificate: None
- HTTP Title: None
Threat Indicators:
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Blacklist Count: 3
- Known Campaigns: None
- Pulsedive Risk: Not available
## Neighborhood Analysis
Subnet: 45.79.190.0/24
- Abuse Density: 0.6667 (66.67%)
- Classification: mostly_clean
- Inherited Risk: 5
- Total Siblings: 3
- Active Siblings: 2
- Threat Siblings: 2
Identified Neighbors:
| IP Address | Risk Score | Authority Score |
|---|---|---|
| 45.79.190.74 | 40 | 60 |
| 45.79.190.95 | 40 | 60 |
## Observation History
The IP has been observed across 19 signal observations. Recent activity (June 2026) shows consistent association with the 45.79.128.0/18 prefix. The subnet exhibits elevated abuse density (66.67%) with two active threat siblings, though the target IP itself shows no persistent malicious activity.
Temporal Indicators:
- Threat Persistence: 0 days
- Is Persistently Malicious: No
- Ownership Changes: 0
- Threat Observation Count: 1
## Relationship Graph
The IP maintains 32 relationships in the intelligence graph, including:
- DNS associations to 45-79-190-104.ip.linodeusercontent.com
- Network affiliation with LINODE
## Recommended Actions
Immediate:
- Increase logging verbosity for traffic from this IP
- Review recent activity patterns and connection logs
Firewall Recommendations:
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 45.79.190.104 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 45.79.190.104 drop` |
| nginx | `deny 45.79.190.104;` |
| pfSense | `45.79.190.104/32` |
| Cloudflare WAF | Block IP with expression: `ip.src eq 45.79.190.104` |
| AWS WAF | Add to rule with addresses: `45.79.190.104/32` |
Operational Notes:
- The IP shows moderate risk but no confirmed malicious activity
- Consider context-dependent blocking (e.g., web-facing services)
- Monitor for behavioral changes given the subnet's elevated abuse density
- No immediate threat action required; maintain monitoring
Analyst Assessment:
The target IP operates from legitimate cloud hosting infrastructure with no active threat indicators. However, the elevated risk score (65) and subnet abuse density warrant enhanced monitoring. No immediate blocking is recommended unless the IP exhibits suspicious connection patterns.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Linode |
| ASN | AS63949 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 45-79-190-104.ip.linodeusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 45-79-190-104.ip.linodeusercontent.com |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 45% | 1 | 8 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 27% | 10 | 22 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-19 09:37:49 UTC |
| Last Seen | 2026-06-28 08:52:16 UTC |
| Profile Built | 2026-06-29 02:56:47 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 31 |
Full dossier details are available via our API.