# Threat Intelligence Briefing: 45.79.227.90
## Executive Summary
IP address 45.79.227.90 is a Linode cloud hosting infrastructure endpoint with a moderate risk score of 55/100. The IP resolves to a mail transfer agent hostname (mta.kermitpalacios.net.eu.org) and operates HTTP services on ports 80 and 8080. While direct threat indicators are absent, the IP appears in three DNSBL lists and has a single threat sibling in its /24 subnet, warranting enhanced monitoring.
## Infrastructure Profile
- Organization: Linode (ASN 63949)
- Location: Fremont, CA, US
- Infrastructure Type: Cloud Computing / Multi-Service Host
- Server Fingerprint: Apache/2.4.37 (CentOS Stream)
- DNS Resolution: mta.kermitpalacios.net.eu.org (eu.org domain)
- Open Ports: TCP/80 (HTTP), TCP/8080 (HTTP-alt)
## Risk Assessment
- Overall Risk Score: 55/100 (Moderate Risk)
- Control Plane: Listed on 3 of 8 DNSBL lists; BGP prefix 45.79.227.90/24 shows route instability
- Operator Score: 0.2609 (Basic classification)
- DNSSEC: Valid
- Notable Flags: Is cloud-hosted, is hosting provider; not Tor/VPN/proxy
## Historical Activity
Analysis of 22 historical observations indicates:
- Cloud infrastructure classification consistent across observations
- Recent threat signal detected on 2026-06-25 with 50 pulse signals attributed to multiple threat feeds
- Historical HTTP fingerprinting shows stable Apache server configuration
- No ownership changes or persistent malicious behavior patterns detected
## Neighborhood Analysis
Subnet 45.79.227.90/24 assessment:
- Abuse Density: 1 (low to moderate)
- Classification: Mostly clean
- Total Siblings: 1 active sibling identified
- Threat Siblings: 1 threat-adjacent IP detected in subnet
## Related Entities
- DNS Associations: mta.kermitpalacios.net.eu.org (multiple records)
- Network: LINODE infrastructure
- Total Relationships: 45 detected entities including DNS hostnames and network associations
## Recommended Actions
Priority: High β Increase logging verbosity and review recent activity from this IP.
Firewall Rules:
- `iptables`: `iptables -A INPUT -s 45.79.227.90 -j DROP`
- `nftables`: `nft add rule inet filter input ip saddr 45.79.227.90 drop`
- `nginx`: `deny 45.79.227.90;`
- `Cloudflare WAF`: Block IP with expression `ip.src eq 45.79.227.90`
- `AWS WAF`: Block CIDR `45.79.227.90/32`
## Intelligence Notes
This IP operates as legitimate cloud hosting infrastructure but exhibits elevated risk characteristics including DNSBL listings and threat-adjacent neighborhood presence. Monitor for changes in DNS resolution patterns, HTTP service behavior, or new threat indicators. The moderate risk score combined with hosting infrastructure classification suggests potential abuse vector rather than confirmed malicious activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Linode |
| ASN | AS63949 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | mta.kermitpalacios.net.eu.org |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | mta.kermitpalacios.net.eu.org |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Multi-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 8080 | http-alt | tcp | β |
| Closed Ports | 22, 25, 443, 3389, 8443 (2 open / 7 scanned) | ||
| Server | Apache/2.4.37 (CentOS Stream) |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 28% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 37% | 2 | 3 |
| Overall | 25% | 10 | 16 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-09 22:11:18 UTC |
| Last Seen | 2026-06-27 16:41:24 UTC |
| Profile Built | 2026-06-28 10:47:36 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 26 |
Full dossier details are available via our API.