IPDebrief

141.94.123.106

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 141.94.123.106/32

Classification: Moderate Risk | Date: Current | Analyst: IPDebrief SOC

## Executive Summary

IP address 141.94.123.106 is a cloud VPS endpoint hosted by OVH SAS (ASN 16276) in Roubaix, France. The IP exhibits moderate risk characteristics with a risk score of 55 and demonstrates multiple DNSBL listings across three of eight monitored lists. Open RDP connectivity and neighborhood threat indicators warrant monitoring and potential firewall restriction.

## Infrastructure Profile

## Risk Assessment

MetricValueAssessment
Risk Score55Moderate Risk
Provider Score0N/A
Authority Score0N/A
DNSBL Listings3/8Listed
Operator Score0.2609Basic
GeoConsensusYesValidated

## Threat Indicators

## Network Exposure

## Temporal Analysis

## Neighborhood Analysis (141.94.123.0/24)

- 141.94.123.104 (Risk: 55, Authority: 60)

- 141.94.123.108 (Risk: 55, Authority: 60)

## Intelligence Relationships

## Recommended Actions

Based on the risk profile and exposure analysis, the following actions are recommended:

1. Block RDP Access: Restrict or monitor TCP/3389 inbound traffic to mitigate remote access exploitation risk

2. Monitor DNSBL Listings: Investigate the three blacklist listings to determine source of reputation degradation

3. Subnet-Level Monitoring: Correlate traffic patterns with neighbor IPs (141.94.123.104, 141.94.123.108) due to shared abuse density

4. Traffic Analysis: Implement logging for outbound connections to understand potential command-and-control or lateral movement patterns

## SOC Analyst Notes

This IP represents a shared OVH VPS infrastructure with elevated risk indicators. The open RDP port combined with DNSBL listings suggests potential misconfiguration or compromise. While no active attacks were identified, the neighborhood abuse density of 33% indicates this subnet warrants continued monitoring. Recommend blocking unsolicited inbound connections and implementing egress filtering.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ซ๐Ÿ‡ท France
Regionโ€”
CityRoubaix
TimezoneEurope/Paris
Latitude48.86
Longitude2.34

๐Ÿข Ownership & Registration

OrganizationOVH SAS
ASNAS16276
Network NameVPS-EU-WEST-RBX-VPS-1
CIDR Block141.94.123.0/24
RIRRIPE
CountryFR
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRvps-a77076d6.vps.ovh.net
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnamesvps-a77076d6.vps.ovh.net

๐Ÿ” DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeSingle-Service Host
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
3389rdptcpโ€”
Closed Ports22, 25, 80, 443, 8080, 8443 (1 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
45%
23
routing
8%
11
services
15%
22
ownership
27%
23
reputation
22%
12
geolocation
25%
22
Overall24%1013
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-25 12:41:29 UTC
Last Seen2026-06-29 01:29:20 UTC
Profile Built2026-06-29 07:33:24 UTC
Data FreshnessLive
Signal Types19
Total Observations21
๐Ÿ” 19 signal types ยท 21 observations collected
This report is generated from 19+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.