# IP Intelligence Briefing: 45.79.190.74/32
## Executive Summary
IP address 45.79.190.74 is a Linode cloud infrastructure endpoint with a moderate risk score of 40. The IP shows no direct threat indicators but operates within a subnet exhibiting elevated abuse density (0.6667). Recommended action is defensive monitoring or blocking pending correlation with other security signals.
## Risk Assessment
- Risk Score: 40/100 (Moderate Risk)
- Provider Score: 0
- Authority Score: 0
- Abuse Confidence: Not assessed
- Classification: Hosting/Cloud infrastructure
## Ownership and Infrastructure
- Organization: Linode
- ASN: 63949 (AKAMAI-LINODE-AP - Akamai Connected Cloud)
- Geolocation: United States, New Jersey, Cedar Knolls
- Infrastructure Type: CloudCompute
- DNS: 45-79-190-74.ip.linodeusercontent.com
- PTR Record: Forward resolution confirmed
## Network Context
The IP resides in subnet 45.79.190.74/24 with the following characteristics:
- Abuse Density: 0.6667 (High)
- Active Siblings: 2 IPs detected
- Threat Siblings: 2 IPs flagged as threats
- Neighbor Risk Scores: 45.79.190.95 (40), 45.79.190.104 (40)
## Threat Intelligence
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0
- Threat Feeds: No indicators
- Campaign Matches: None detected
## Anomalies and Observations
- Geolocation Validation Issue: RTT anomaly detected (19ms observed vs. 119.8ms minimum possible for 5,989km distance). This suggests either reporting error or potential proxy/routing anomaly.
- Route Stability: False (control plane indicates instability)
- Open Ports: None detected (Firewalled/No Services)
- TLS Certificates: Not configured
## Historical Analysis
19 observations recorded over the monitoring period. Recent signals consistently identify the IP as Linode cloud infrastructure with no pattern of escalating malicious behavior. No persistent malicious activity detected (threat persistence days: 0).
## Recommended Actions
Based on risk profile, the following defensive measures are recommended:
Firewall Rules:
- `iptables -A INPUT -s 45.79.190.74 -j DROP`
- `nft add rule inet filter input ip saddr 45.79.190.74 drop`
- `nginx: deny 45.79.190.74`
Cloud/WAF Configuration:
- Cloudflare WAF: Block IP with expression `ip.src eq 45.79.190.74`
- AWS WAF: Add 45.79.190.74/32 to block list
## Intelligence Narrative
IP 45.79.190.74 represents a Linode cloud hosting endpoint. While no direct threat indicators are present, the elevated abuse density of the /24 subnet and the presence of 2 threat-sibling IPs warrant defensive attention. The IP shows no services exposed (firewalled configuration), reducing immediate exploitation risk. However, the geolocation validation anomaly and route instability suggest potential misconfiguration or proxy usage. SOC analysts should monitor for any emerging threat indicators in correlation with the flagged sibling IPs (45.79.190.95, 45.79.190.104).
Priority: Monitor
Confidence: Medium
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Linode |
| ASN | AS63949 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 45-79-190-74.ip.linodeusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 45-79-190-74.ip.linodeusercontent.com |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 21% | 2 | 2 |
| routing | 20% | 1 | 1 |
| services | 21% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 20% | 1 | 2 |
| geolocation | 34% | 2 | 3 |
| Overall | 23% | 10 | 13 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:22 UTC |
| Last Seen | 2026-06-27 05:38:08 UTC |
| Profile Built | 2026-06-28 05:44:46 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 26 |
Full dossier details are available via our API.