# THREAT INTELLIGENCE BRIEFING
## Target: 209.141.37.194/32
Executive Summary
The IP address 209.141.37.194 presents a low-risk profile with a risk score of 25. The address is registered to FranTech Solutions (BuyVM), a colocation hosting provider based in Las Vegas, NV. Current threat indicators show minimal operator involvement (0.1304 score), no active services, and no persistent malicious behavior. The subnet classification is "mostly_clean" with low abuse density.
Ownership and Infrastructure
- Organization: FranTech Solutions
- ASN: 53667
- RIR: ARIN
- Network Role: Colocation Hosting (Frantech/BuyVM)
- Geolocation: Las Vegas, NV, United States
- BGP Prefix: 209.141.32.0/19
- Routing Status: Stable (AS path: 6939 53667)
Network Services Assessment
- Open Ports: None detected
- TLS Certificates: None present
- HTTP Services: Inactive
- DNS Resolution: No forward resolution, no PTR hostnames
- Infrastructure Type: Firewalled / No Services
Threat Indicators
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0 (current)
- DNSBL Listed: 1 of 8 lists
- Known Campaigns: None identified
- Abuse Confidence: Minimal
Temporal Analysis
- Total Observations: 25 historical signals
- Threat Persistence: 0 days
- Ownership Changes: 0
- Not Persistently Malicious: Confirmed
- Historical Anomaly: One observation on 2026-06-25 showed max severity "high" with 8 total blacklist listings (1 active). This appears resolved with current operator score returning to minimal (0.1304).
Network Neighborhood
- Subnet: 209.141.37.194/24
- Abuse Density: 0
- Classification: Mostly Clean
- Active Siblings: 2 of 2 total
- Neighbor IP: 209.141.37.7 (Risk Score: 25, Authority Score: 60)
- Threat Siblings: 2 detected within subnet
Relationship Graph
- Total Relationships: 26
- Primary Association: PONYNET-04 network (Same Network type)
- Relationship Type: Network-level associations only
Recommended Actions
Based on current risk profile (Score: 25), no immediate blocking or firewall rules are recommended. The IP exhibits benign characteristics consistent with a standard colocation hosting environment.
Monitoring Recommendation: Continue standard logging and observation. No elevated threat activity detected.
Intelligence Assessment
This IP address represents a low-priority monitoring target. The address functions as a standard hosting infrastructure component with no evidence of active malicious use. Historical signals indicate one resolved blacklist event that does not correlate with current threat posture. Network neighborhood and routing stability support a benign classification.
Classification: LOW RISK / COLLOCATION HOSTING
Priority: STANDARD MONITORING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | FranTech Solutions |
| ASN | AS53667 |
| Network Name | β |
| CIDR Block | 209.141.32.0/19 |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 5 |
| routing | 24% | 2 | 3 |
| services | 15% | 2 | 2 |
| ownership | 32% | 3 | 5 |
| reputation | 27% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 28% | 12 | 21 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-09 17:41:27 UTC |
| Last Seen | 2026-06-27 16:10:18 UTC |
| Profile Built | 2026-06-28 16:15:31 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 31 |
Full dossier details are available via our API.