# IP Intelligence Briefing: 45.79.190.95/32
## Executive Summary
IP address 45.79.190.95 operates on Linode cloud infrastructure (ASN 63949) with a moderate risk profile (score: 40). The IP is registered to US-based Cedar Knolls, NJ, but exhibits geolocation anomalies inconsistent with the claimed location. Neighborhood analysis indicates elevated abuse density (66.67%) within the /24 subnet, with two sibling IPs showing similar risk characteristics.
## Current Risk Assessment
- Overall Risk Score: 40 (Moderate Risk)
- Infrastructure Type: CloudCompute (Linode hosting platform)
- Classification: Single-Service Host
- Abuse Confidence: High severity flagged in one of eight blacklist checks
## Technical Profile
Network Classification:
- ASN: 63949 (AKAMAI-LINODE-AP / Akamai Connected Cloud, SG)
- BGP Prefix: 45.79.176.0/20
- Route Stability: Stable (no route changes in 30 days)
- DNSBL Status: Listed on 1 of 8 threat feeds
Active Services:
- Port 22 (SSH) β OpenSSH 8.9p1 Ubuntu-3ubuntu0.15
- No HTTP/HTTPS services detected
- No TLS certificates observed
DNS Resolution:
- PTR: 45-79-190-95.ip.linodeusercontent.com
- Forward confirmed: Yes
- Email Authentication: No SPF or DMARC records present
## Geolocation Anomalies
Critical RTT discrepancy detected:
- Reported distance: 5,988.6 km
- Observed RTT: 19ms
- Minimum possible RTT for claimed distance: 119.8ms
- Assessment: Geolocation data appears unreliable; actual origin may differ significantly from reported US location.
## Neighborhood Analysis
Subnet: 45.79.190.0/24
- Total siblings: 3
- Active siblings: 2
- Threat siblings: 2
- Abuse density: 66.67%
- Inherited risk score: 5
Notable Neighbors:
- 45.79.190.74 (Risk: 40, Authority: 60)
- 45.79.190.104 (Risk: 40, Authority: 60)
## Relationship Graph
63 total relationships identified:
- DNS associations to linodeusercontent.com hostnames
- Network associations with LINODE infrastructure
- No malicious campaigns or certificate matches detected
## Historical Observations
28 signal observations recorded. Key temporal signals:
- June 2026: DNSBL listings with high severity
- Consistent cloud infrastructure classification (Linode)
- No persistent malicious behavior detected
- Threat observation count: 1
## Recommended Actions
Based on IPDebrief risk assessment:
Immediate Mitigation:
```bash
# iptables
iptables -A INPUT -s 45.79.190.95 -j DROP
# nftables
nft add rule inet filter input ip saddr 45.79.190.95 drop
# nginx
deny 45.79.190.95;
```
Cloud Platform Integration:
- Cloudflare WAF: Block IP with expression `ip.src eq 45.79.190.95`
- AWS WAF: Add 45.79.190.95/32 to web ACL block list
## Intelligence Assessment
This IP exhibits moderate risk primarily due to:
1. DNSBL presence with high-severity listing
2. Elevated neighborhood abuse density (66.67%)
3. Unverified geolocation data suggesting potential masking
4. Open SSH service without additional hardening indicators
Threat Actor Profile: None identified. No known campaigns, attacker indicators, or spam source classifications.
Recommended SOC Action: Monitor but do not block unless additional threat intelligence confirms malicious activity. The moderate risk score combined with cloud hosting infrastructure suggests potential for legitimate use with some abuse potential.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Linode |
| ASN | AS63949 |
| Network Name | β |
| CIDR Block | 45.79.176.0/20 |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 45-79-190-95.ip.linodeusercontent.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 45-79-190-95.ip.linodeusercontent.com |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 45% | 2 | 5 |
| routing | 31% | 2 | 4 |
| services | 15% | 2 | 2 |
| ownership | 27% | 3 | 4 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 30% | 12 | 21 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-19 15:39:10 UTC |
| Last Seen | 2026-06-28 09:22:16 UTC |
| Profile Built | 2026-06-29 03:27:32 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 31 |
Full dossier details are available via our API.