# IP Intelligence Briefing: 145.239.81.63/32
Classification: LOW RISK | Date: Current | Status: Monitored
## Executive Summary
IP address 145.239.81.63 is a cloud-hosted infrastructure endpoint belonging to OVH Sp. z o. o. (AS16276) in Wroclaw, Poland. The IP demonstrates low-risk characteristics with a risk score of 25. No active threat indicators or malicious activity have been observed. The IP resolves to a VPS hostname (vps-c1ecfe85.vps.ovh.net) and operates within a generally clean subnet environment.
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **Provider** | OVH Sp. z o. o. (AS16276) |
| **Network** | OVH-VPS (145.239.80.0/20) |
| **Location** | Wroclaw, Lower Silesia, Poland |
| **Infrastructure Type** | CloudCompute, Hosting |
| **DNS Resolution** | vps-c1ecfe85.vps.ovh.net |
| **Services** | None detected (Firewalled / No Services) |
| **Open Ports** | None |
## Threat Assessment
Risk Score: 25 (Low Risk)
Threat Indicators:
- No known attacker reputation
- No spam source activity
- Not a Tor exit node
- Zero blacklist count
- No known campaigns associated
Control Plane Indicators:
- DNSBL Listed: 1 of 8 total lists
- Operator Score: 0.2609 (Basic)
- No MoAS or route instability detected
- DNSSEC validation: Valid
## Neighborhood Analysis
The /24 subnet (145.239.81.0/24) shows minimal abuse activity:
- Abuse Density: 0.0 (0% of neighbors flagged as high-risk)
- Neighbor Count: 1 active neighbor (145.239.81.31, Risk Score: 25)
- Subnet Classification: Mostly Clean
- Risk Distribution: 1 low-risk, 0 medium/high-risk
## Observation History
Total Observations: 18 signals recorded
Recent Activity:
- June 21, 2026: Latest observations recorded with Basic operator classification
- June 16, 2026: Subnet classification maintained as "mostly_clean"
- No ownership changes detected
- No persistent malicious behavior observed
Temporal Indicators:
- Threat Persistence Days: 0
- Threat Observation Count: 0
- Is Persistently Malicious: False
## Relationship Graph
9 Identified Relationships:
- DNS Associations: Multiple entries pointing to vps-c1ecfe85.vps.ovh.net
- Network Associations: Same Network (OVH-VPS)
- No certificate matches or correlated IPs identified
## Recommended Actions
Current Status: No blocking recommended
Monitoring Guidelines:
- The IP presents as a legitimate cloud VPS endpoint
- No immediate threat mitigation required
- Maintain standard logging and monitoring for baseline behavior
- Watch for any changes in service exposure or threat indicators
Firewall Rules:
- No specific firewall rules required based on current risk profile
- Standard egress/ingress policies apply
---
Analysis Notes: This IP represents a standard OVH VPS infrastructure endpoint in Poland with no active malicious indicators. The subnet environment is clean, and the IP shows no signs of abuse or exploitation. SOC teams should treat this as low-risk infrastructure with standard monitoring procedures.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | OVH Sp. z o. o. |
| ASN | AS16276 |
| Network Name | OVH-VPS |
| CIDR Block | 145.239.80.0/20 |
| RIR | RIPE |
| Country | PL |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vps-c1ecfe85.vps.ovh.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | vps-c1ecfe85.vps.ovh.net |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 21% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 13% | 1 | 1 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 21% | 2 | 2 |
| Overall | 19% | 9 | 11 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-06-06 19:45:14 UTC |
| Last Seen | 2026-06-21 13:21:15 UTC |
| Profile Built | 2026-06-21 13:53:47 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 22 |
Full dossier details are available via our API.