# IP Intelligence Briefing: 45.61.187.148
## Executive Summary
IP address 45.61.187.148 operates from Frantech Solutions (Frantech/BuyVM) infrastructure in Miami, Florida. The IP presents a Low Risk profile (Risk Score: 25) with no active threat indicators, though the subnet contains elevated risk neighbors that warrant contextual awareness.
---
## Current Risk Profile
- Risk Score: 25/100 (Low Risk)
- Provider: Frantech Solutions (BuyVM) - ASN 53667
- Network: PONYNET-15 (45.61.128.0/18)
- Geolocation: US, Florida, Miami (±2500km accuracy)
- Infrastructure Type: Colocation Hosting
- Abuse Confidence: Not flagged as known attacker, Tor exit, or spam source
---
## Network Characteristics & Services
- Open Ports: TCP 3389 (RDP) detected
- DNS Resolution: v2-us-1.v2ray.cc
- DNSBL Status: Listed on 1 of 8 queried blacklists
- Network Role: Single-Service Host
- Certificate/SSL: No TLS certificate observed
---
## Neighborhood Analysis (45.61.187.0/24)
The /24 subnet contains 10 active sibling IPs with an abuse density of 0.111. Risk distribution indicates:
- High Risk: 1 IP (45.61.187.220 - Risk Score: 80)
- Medium Risk: 5 IPs (Risk Scores: 25-40)
- Low Risk: 3 IPs (Risk Scores: 25)
The target IP's inherited risk is minimal (5/100), suggesting it operates as a clean endpoint within this subnet.
---
## Historical Signals (24 Observations)
Recent activity shows:
- Network Classification: Stable hosting provider classification since August 2026
- Subnet Classification: "Mostly clean" with 2 threat siblings
- Geolocation Signals: US location confirmed with 0.35 confidence
- Operator Score: 0.1304 (Minimal)
No escalation in threat activity observed over the observation period.
---
## Relationships & Indicators
- DNS Association: Strong correlation with v2-us-1.v2ray.cc hostname (12 relationship links)
- Network Relationships: Multiple "Same Network" entries to PONYNET-15
- Campaign Activity: None detected
- Correlated IPs: 0
---
## SOC Recommendations
No immediate blocking recommended based on current risk profile. However, consider:
1. Monitor RDP Exposure: TCP 3389 open on a hosting infrastructure IP
2. Contextual Neighbor Awareness: Subnet contains 1 high-risk IP (45.61.187.220)
3. DNSBL Monitoring: One blacklist listing warrants periodic revalidation
4. Hostname Investigation: v2-us-1.v2ray.cc should be assessed for potential proxy/V2Ray service usage
Action Status: No automated firewall rules generated. Manual review recommended only if this IP appears in active threat indicators or correlates with malicious activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | FranTech Solutions |
| ASN | AS53667 |
| Network Name | PONYNET-15 |
| CIDR Block | 45.61.128.0/18 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | v2-us-1.v2ray.cc |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | v2-us-1.v2ray.cc |
🔐 DNS Hygiene
| Hygiene Score | 0% (None) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting — Infrastructure provider without advanced routing |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 3389 | rdp | tcp | — |
| Closed Ports | 22, 25, 80, 443, 8080, 8443 (1 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS53667 |
| Network Prefix | 45.61.184.0/22 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 20% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 17% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 17% | 2 | 3 |
| Overall | 15% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-17 11:04:57 UTC |
| Last Seen | 2026-09-25 14:22:54 UTC |
| Profile Built | 2026-09-25 08:21:33 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 27 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 45.61.187.148
Who owns the IP address 45.61.187.148?
45.61.187.148 is registered to FranTech Solutions. The address falls within the 45.61.128.0/18 network block. Registration is held at ARIN.
Where is 45.61.187.148 located?
Geolocation data places 45.61.187.148 in Miami, Florida, United States. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 45.61.187.148 malicious or safe?
45.61.187.148 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 45.61.187.148?
The reverse DNS (PTR) record for 45.61.187.148 is v2-us-1.v2ray.cc. This hostname is not forward-confirmed, so it should be treated as a weak signal.
What ports are open on 45.61.187.148?
Responsive ports observed on 45.61.187.148 include 3389. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.
Is 45.61.187.148 a VPN, proxy, or data center address?
45.61.187.148 is classified as hosting infrastructure based on network ownership and behavioural analysis.