IP Intelligence Briefing: 45.9.148.188/32
Executive Summary
IP 45.9.148.188 is a confirmed Tor exit node with moderate risk profile (Risk Score: 59). The address is associated with NiceIT-NL (ASN 49447) in Amsterdam, Netherlands. The IP exhibits Tor exit node indicators and is listed on one DNSBL entry. The neighborhood shows elevated abuse density (0.75) with 3 out of 4 sibling IPs flagged as threats.
Network Profile
- Owner/Operator: Kimon S., NiceIT-NL (ASN 49447)
- Geolocation: Amsterdam, North Holland, Netherlands (NL)
- CIDR Block: 45.9.148.128/25
- ASN Origin: 45.9.148.0/24 (RIPE NCC, registered 2019-04-23)
- BGP Stability: Not route stable (1 route change in 30 days)
- Operator Score: 0.2174 (Minimal)
Threat Indicators
- Tor Exit Node: Confirmed active (isTorExit: true)
- Blacklist Status: Listed on 1 blacklist / 8 DNSBL lists
- Risk Classification: Moderate Risk (Score: 59)
- Network Role: Tor Exit Node / Web Server
Network Services
- Open Ports: 80/TCP (HTTP), 443/TCP (HTTPS), 22/TCP (SSH)
- TLS Certificate: Self-signed/mismatched certificate (CN=www.qbkcxfpbgkndbr.net issued by CN=www.2wd5knmny.com)
- DNS Status: No forward resolution, PTR hostnames not confirmed
Neighborhood Analysis (45.9.148.0/24)
- Abuse Density: 0.75 (elevated)
- Classification: Mostly clean
- Total Siblings: 4
- Active Siblings: 4
- Threat Siblings: 3
- Sibling Risk Scores:
- 45.9.148.50: Risk 49, Authority 60
- 45.9.148.122: Risk 66, Authority 50
- 45.9.148.165: Risk 59, Authority 50
Observation History
- Total Observations: 29 signals recorded
- Recent Activity: Tor exit node detection confirmed (2026-08-08)
- ASN Age: 2,664 days (registered April 23, 2019)
- Geolocation Confidence: 0.4 (moderate uncertainty on NL placement)
Recommended Actions
1. Block inbound traffic from 45.9.148.0/24 at perimeter firewall due to confirmed Tor exit node activity
2. Monitor outbound connections from internal hosts to this subnet for potential command-and-control traffic
3. Review SSH access (port 22) from this IP if connections are attempted
4. Add to threat feed for automated blocking in WAF/IPS systems
Relationship Graph
- 39 relationships identified
- Primary associations: NiceIT-NL network (multiple Same Network entries)
- No known campaign correlations or certificate matches detected
Assessment
The IP is actively used as a Tor exit node, which is consistent with the threat profile. The elevated neighborhood abuse density suggests this subnet may be utilized for proxying or anonymity services. The subnet is not route-stable, indicating potential infrastructure fluidity. SOC teams should treat this IP as untrusted and implement appropriate blocking policies.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Kimon S. |
| ASN | AS49447 |
| Network Name | NiceIT-NL |
| CIDR Block | 45.9.148.128/25 |
| RIR | ARIN |
| Country | NL |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Tier 3 — Basic operator with some routing infrastructure |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 443 | https | tcp | — |
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | 2025-11-08T00:00:00+00:00 |
| Valid Until | 2026-10-28T00:00:00+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 190 days |
🛡️ Public Network Snapshot
| Origin ASN | AS49447 |
| Network Prefix | 45.9.148.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 20% | 2 | 4 |
| routing | 17% | 2 | 3 |
| services | 28% | 2 | 4 |
| ownership | 27% | 3 | 5 |
| reputation | 16% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 22% | 12 | 22 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-17 12:38:37 UTC |
| Last Seen | 2026-09-02 18:30:38 UTC |
| Profile Built | 2026-09-02 18:38:11 UTC |
| Data Freshness | Live |
| Signal Types | 27 |
| Total Observations | 36 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 45.9.148.188
Who owns the IP address 45.9.148.188?
45.9.148.188 is registered to Kimon S.. The address falls within the 45.9.148.128/25 network block. Registration is held at ARIN.
Where is 45.9.148.188 located?
Geolocation data places 45.9.148.188 in Amsterdam, North Holland, Netherlands. The local time zone is Europe/Amsterdam. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 45.9.148.188 malicious or safe?
45.9.148.188 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 45.9.148.188?
Responsive ports observed on 45.9.148.188 include 80, 443, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.