# IP Intelligence Briefing: 148.113.170.126
Classification: Low Risk โ No Active Threat Indicators
Date: 2026-08-12
Analyst: IPDebrief Intelligence
## Executive Summary
IP address 148.113.170.126 is classified as low risk with no active threat indicators. The address is hosted on OVH cloud infrastructure in Canada and functions as a standard web server with no evidence of malicious activity, blacklisting, or association with known threat campaigns.
## Technical Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 0 (Low Risk) |
| **ASN** | 16276 (OVH Hosting, Inc.) |
| **Network** | 148.113.170.0/24 |
| **Location** | Canada (CA) |
| **Infrastructure Type** | Cloud Compute (Cloud) |
| **Hostname** | vp10.ht207.com |
| **Reverse DNS** | vp10.ht207.com |
| **Services** | HTTP (80), HTTPS (443), SSH (22) |
| **Web Server** | Apache |
| **TLS Certificate** | Let's Encrypt (mail.icarusmx.com) |
## Threat Assessment
- Blacklist Status: Not listed (0/8 DNSBL lists)
- Known Attack Source: No
- Spam Source: No
- Tor Exit Node: No
- Abuse Confidence Score: Not applicable
- Threat Persistence: None observed
## Network Context
- Subnet Abuse Density: 0 (clean subnet)
- Threat Siblings: 0
- Control Plane: BGP prefix 148.113.128.0/17, operator score 0.2609 (Basic)
- Route Stability: Unstable (false)
## Historical Observations
Analysis of 22 observations spanning the observation window indicates consistent benign behavior:
- Most recent classification: Clean (2026-08-12)
- No risk escalation detected over time
- Average ownership stability maintained
- No observed threat activity patterns
## Related Entities
- DNS Associations: vp10.ht207.com (repeated associations)
- Network Associations: SD-BHS-BHS0801A-MAGGIE-INFRA002-IP-2
- No Correlated Threat IPs: None identified
## Recommended Actions
No blocking or filtering actions recommended at this time. The IP address presents no defensive security concerns.
## SOC Analyst Notes
This IP is a standard cloud-hosted web server with typical hosting provider characteristics (OVH). The presence of SSH port 22 is consistent with infrastructure management requirements. The TLS certificate subject (mail.icarusmx.com) differs from the hostname (vp10.ht207.com), which may warrant standard validation but does not indicate malicious intent in isolation. No firewall rules or monitoring alerts are recommended based on current threat intelligence.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | OVH Hosting, Inc. |
| ASN | AS16276 |
| Network Name | SD-BHS-BHS0801A-MAGGIE-INFRA002-IP-2 |
| CIDR Block | 148.113.170.0/24 |
| RIR | ARIN |
| Country | Canada |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vp10.ht207.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | vp10.ht207.com |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | 1/2 domains |
| DMARC | 0/2 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
| Domains Checked | 2 domains |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | Apache |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.9 |
๐ TLS Certificate
| SANs | mail.icarusmx.com |
| Valid From | 2026-07-06T04:49:11+00:00 |
| Valid Until | 2026-10-04T04:49:10+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 89 days |
| Serial Number | 05BE32A8041AF7298D16533E231CC59F39B0 |
| Thumbprint | 61383EE5B30F66762E95BE9E4F1F1F0B8FD2AB56 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 21% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 1 |
| geolocation | 13% | 1 | 1 |
| Overall | 20% | 9 | 11 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-23 20:05:04 UTC |
| Last Seen | 2026-08-12 17:54:47 UTC |
| Profile Built | 2026-08-12 18:03:11 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 25 |
Full dossier details are available via our API.