IPDebrief

146.59.228.194

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

Threat Intelligence Briefing: IP 146.59.228.194/32

IP Overview

Key Findings

1. Ownership & Infrastructure:

- Owned by OVH SAS, a cloud service provider.

- Associated with the `VPS-GRA8` network, likely a virtual private server.

- No residential/mobile carrier links; infrastructure is hosted.

2. Threat Indicators:

- Moderate Risk: Observed in 18 signals over 30 days, including 8 threat intelligence feeds (e.g., DNSBL listings).

- No Active Threats: No known malicious campaigns, spam, or Tor exit nodes.

- Subnet Cleanliness: Subnet abuse density is 0, with no malicious siblings in the 146.59.228.0/24 block.

3. Network Behavior:

- DNS Associations: Linked to `vps-289d9810.vps.ovh.net` (OVH-hosted hostname).

- Open Ports/Services: No open ports or TLS certificates detected.

- Routing Stability: BGP prefix `146.59.0.0/16` shows stable routing with no recent changes.

4. Historical Trends:

- Consistent Profile: No significant changes in risk scores or geolocation over the past 30 days.

- DNSSEC Valid: DNS records are valid, with SPF/DKIM email authentication enabled.

Recommended Actions

Conclusion

This IP is part of a legitimate OVH cloud network with no current evidence of malicious activity. While it poses moderate risk due to historical threat feed mentions, its subnet remains clean. SOC teams should maintain baseline monitoring and verify any unexpected behavior.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ซ๐Ÿ‡ท France
Regionโ€”
CityRoubaix
TimezoneEurope/Paris
Latitude48.86
Longitude2.34

๐Ÿข Ownership & Registration

OrganizationOVH SAS
ASNAS16276
Network NameVPS-GRA8
CIDR Block146.59.228.0/22
RIRARIN
CountryFR
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRvps-289d9810.vps.ovh.net
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnamesvps-289d9810.vps.ovh.net

๐Ÿ” DNS Hygiene

Hygiene Score80% (Excellent)
SPF1/2 domains
DMARC1/2 domains
FCrDNSVerified
DNSSECValid
CAANot configured
Domains Checked2 domains

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeWeb Server
Network TierTier 3 โ€” Basic operator with some routing infrastructure
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
443httpstcpโ€”
22sshtcp
8080http-alttcpโ€”
Closed Ports25, 80, 3389, 8443 (3 open / 7 scanned)
Servernginx
HTTP Titleโ€”
SSH VersionSSH-2.0-OpenSSH_8.2p1 Ubuntu-4ubuntu0.13

๐Ÿ” TLS Certificate

๐Ÿ”’
CN=proxy1.yallalowwa1.live
Issued by CN=R13, O=Let's Encrypt, C=US
Self-signed: No
SANsproxy1.yallalowwa1.live
Valid From2026-04-21T12:03:24+00:00
Valid Until2026-07-20T12:03:23+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period89 days
Serial Number06F86B9A75C0B9C0ED1AC50460B098632744
ThumbprintF30055C2C6C57796FE750F1AB216E68BC511FBB9

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
32%
23
routing
13%
11
services
32%
23
ownership
30%
23
reputation
28%
13
geolocation
27%
23
Overall27%1016
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-31 23:33:20 UTC
Last Seen2026-06-21 06:47:39 UTC
Profile Built2026-06-21 06:53:14 UTC
Data FreshnessLive
Signal Types23
Total Observations26
๐Ÿ” 23 signal types ยท 26 observations collected
This report is generated from 23+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.