## Intelligence Briefing: IP 145.239.64.13/32
Classification: LOW RISK | Status: Passive Monitoring | Date: 2026-08-12
Summary
Target IP 145.239.64.13 is a cloud-hosted infrastructure asset belonging to OVH SAS (ASN 16276) with a risk score of 25 (Low Risk). The IP resolves to a WordPress-based web presence hosted on OVH's SD-GRA2 network in France. No active threat indicators or malicious activity observed.
Infrastructure Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 25 (Low Risk) |
| **Organization** | OVH SAS (ASN 16276) |
| **Network Block** | 145.239.64.0/22 |
| **Geolocation** | France (FR) |
| **Infrastructure Type** | CloudCompute / Hosting |
| **DNS Classification** | Clean |
Network Services & Application Layer
- Open Ports: 80/tcp (HTTP), 443/tcp (HTTPS), 8443/tcp (HTTPS-ALT)
- Web Server: nginx (HTTP/2 enabled)
- Application Stack: PHP 8.2.33
- TLS Certificate: Let's Encrypt (CN=hopeful-williamson.145-239-64-13.plesk.page)
- Security Headers: HSTS disabled, CSP not implemented
Domain & Email Infrastructure
- Primary Domain: restauranteambivium.com
- DNS Records: SPF configured (v=spf1 include:spf.protection.outlook.com -all)
- DMARC Policy: Not configured
- Hosted Domains: 0
- PTR Record: ns3085904.ip-145-239-64.eu
Threat Intelligence Assessment
- Abuse Confidence Score: Not applicable (clean classification)
- Blacklist Status: Listed on 1 of 8 DNSBLs (low-severity listing)
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Threat Feeds: No correlated campaigns detected
- Control Plane: Route stability inconsistent; DNSSEC valid
Observation History (26 signals)
Recent observations from 2026-08-12 indicate:
- WordPress administrative interface access patterns (wp-admin, admin-ajax.php)
- XML sitemap generation (wp-sitemap.xml)
- Consistent HTTP/2 protocol usage
- Average Time to First Byte: 1246ms
- No persistent malicious behavior observed over monitoring period
Neighborhood Analysis
- Subnet: 145.239.64.0/24
- Abuse Density: 0%
- Classification: Clean
- Threat Siblings: 0 detected
- Active Siblings: 1 (target IP only)
Recommended Security Actions
No immediate blocking or filtering actions recommended. The IP presents a standard cloud-hosted web server profile with legitimate commercial hosting characteristics.
Intelligence Notes
This IP belongs to a residential/business cloud hosting environment (OVH). The WordPress stack and Plesk page hosting suggest small-to-medium enterprise web presence. SPF configuration is present but DMARC is absent, indicating suboptimal email authentication posture. The single low-severity DNSBL listing warrants monitoring but does not warrant immediate action. No evidence of compromise or abuse activity observed.
---
*Intel produced from IPDebrief threat intelligence platform. Data sourced from passive network monitoring and reputation feeds.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | OVH SAS |
| ASN | AS16276 |
| Network Name | SD-GRA2 |
| CIDR Block | 145.239.64.0/22 |
| RIR | RIPE |
| Country | FR |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | ns3085904.ip-145-239-64.eu |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | ns3085904.ip-145-239-64.eu |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | 2/3 domains |
| DMARC | 0/3 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
| Domains Checked | 3 domains |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 8443 | https-alt | tcp | โ |
| Closed Ports | 22, 25, 3389, 8080 (3 open / 7 scanned) | ||
| Server | nginx |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | hopeful-williamson.145-239-64-13.plesk.page |
| Valid From | 2026-06-22T06:07:41+00:00 |
| Valid Until | 2026-09-20T06:07:40+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 89 days |
| Serial Number | 0510D769016ADC79DAE78E89F568CC00F2E6 |
| Thumbprint | 1D5D5F4E74327302CAC44D3A91EB0FCB4BF19204 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 15% | 1 | 2 |
| geolocation | 13% | 1 | 1 |
| Overall | 21% | 9 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-23 20:05:02 UTC |
| Last Seen | 2026-08-12 17:54:09 UTC |
| Profile Built | 2026-08-12 18:03:11 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 26 |
Full dossier details are available via our API.