45.61.187.30 Threat Intelligence and Host Information
General
This page contains threat intelligence information for the IPv4 address 45.61.187.30 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.
Potentially Malicious Host 🟡 45/100
Host and Network Information
-
Mitre ATT&CK IDs: T1110 - Brute Force
-
Tags: block list, brute force, Bruteforce, Brute-Force, china mobile, columns, company limited, hk abusehandler, hong kong, hurricane us, info, network, notice, nxdomain, pgp sign, ssh, SSH, timeout, unknown, us none
-
View other sources: Spamhaus VirusTotal
- Country: United States
- Network:
- Noticed: 7 times
- Protocols Attacked: ssh
- Countries Attacked: Australia
Open Ports Detected
10000 10001 10004 10005 10008 10009 10012 10013 10015 10017 10018 10020 10022 10023 10026 10030 10033 10037 10040 10043 10047 10048 10049 10050 10068 10080 10081 10083 10084 10087 10089 10093 10100 10101 10123 10180 10181 10205 10225 10243 10249 10250 10254 10256 10324 10348 10380 10399 10443 10477 10533 10554 10892 10909 10911 10934 11000 11001 11027 11075 11101 11110 11111 11112 11180 11184 11210 11211 11288 11300 11371 11401 11434 11601 11602 11680 11681 11701 12000 12016 12019 12082 12084 12101 12103 12106 12107 12108 12109 12110 12113 12117 12118 12120 12122 12125 12127 12129 12130 12134 12135 12136 12137 12139 12142 12144 12145 12146 12154 12156 12157 12158 12159 12160 12161 12164 12165 12166 12167 12169 12170 12173 12175 12178 12179 12180 12181 12183 12184 12187 12188 12189 12190 12191 12194 12195 12198 12201 12202 12204 12206 12207 12210 12215 12219 12220 12223 12225 12228 12229 12230 12238 12239 12242 12243 12244 12245 12246 12248 12249 12250 12251 12252 12253 12255 12257 12261 12263 12264 12267 12268 12269 12272 12275 12276 12278 12280 12281 12283 12284 12285 12288 12289 12291 12292 12293 12294 12295 12296 12302 12303 12304 12305 12306 12308 12311 12312 12313 12314 12315 12317 12319 12320 12321 12322 12325 12327 12328 12329 12330 12333 12335 12337 12340 12341 12345 12346 12349 12350 12352 12353 12357 12358 12361 12365 12367 12369 12370 12371 12377 12378 12379 12380 12381 12382 12390 12392 12393 12397 12399 12400 12401 12406 12407 12413 12414 12416 12418 12419 12422 12423 12425 12427 12428 12432 12433 12434 12435 12436 12438 12440 12447 12448 12449 12450 12455 12458 12459 12460 12461 12462 12463 12466 12468 12469 12471 12472 12474 12475 12476 12477 12478 12481 12482 12486 12487 12492 12499 12501 12502 12503 12507 12508 12511 12514 12515 12519 12521 12522 12525 12527 12530 12531 12533 12537 12538 12540 12544 12547 12548 12549 12551 12552 12554 12556 12557 12558 12559 12561 12562 12571 12574 12577 12579 12580 12581 12584 12585 12587 12589 12601 12902 13000 22
CVEs Detected
CVE-2007-2768 CVE-2008-3844 CVE-2016-20012 CVE-2019-16905 CVE-2020-14145 CVE-2020-15778 CVE-2021-36368 CVE-2021-41617 CVE-2023-38408 CVE-2023-48795 CVE-2023-51385 CVE-2023-51767 CVE-2025-26465 CVE-2025-32728
Map
Whois Information
- NetRange: 45.61.128.0 - 45.61.191.255
- CIDR: 45.61.128.0/18
- NetName: PONYNET-15
- NetHandle: NET-45-61-128-0-1
- Parent: NET45 (NET-45-0-0-0-0)
- NetType: Direct Allocation
- OriginAS:
- Organization: FranTech Solutions (SYNDI-5)
- RegDate: 2015-01-02
- Updated: 2015-01-02
- Ref: https://rdap.arin.net/registry/ip/45.61.128.0
- OrgName: FranTech Solutions
- OrgId: SYNDI-5
- Address: 1621 Central Ave
- City: Cheyenne
- StateProv: WY
- PostalCode: 82001
- Country: US
- RegDate: 2010-07-21
- Updated: 2024-11-25
- Ref: https://rdap.arin.net/registry/entity/SYNDI-5
- OrgTechHandle: FDI19-ARIN
- OrgTechName: Dias, Francisco
- OrgTechPhone: +1-778-977-8246
- OrgTechEmail: admin@frantech.ca
- OrgTechRef: https://rdap.arin.net/registry/entity/FDI19-ARIN
- OrgAbuseHandle: FDI19-ARIN
- OrgAbuseName: Dias, Francisco
- OrgAbusePhone: +1-778-977-8246
- OrgAbuseEmail: admin@frantech.ca
- OrgAbuseRef: https://rdap.arin.net/registry/entity/FDI19-ARIN
Links to attack logs
digitaloceantoronto-ssh-bruteforce-ip-list-2025-09-08
Share on: