INTELLIGENCE BRIEFING: 148.113.20.192/32
Classification: Low Risk | Geolocation: Mumbai, Maharashtra, India (IN) | Provider: OVH Cloud (ASN 16276)
Risk Assessment
The IP address 148.113.20.192/32 presents a low-risk threat profile with an overall risk score of 25. The address is classified within OVH's cloud infrastructure (148.113.0.0/18) and operates in Mumbai, India. No malicious indicators were identified: the IP is not a known attacker, Tor exit node, proxy, or spam source. Blacklist analysis shows the IP appears on 1 of 8 threat feeds, with maximum severity rated high.
Network Characteristics
- Infrastructure Type: CloudCompute hosting environment
- Service Status: No open ports detected; services classified as "Firewalled / No Services"
- DNS Resolution: Reverse DNS records resolve to ns5024995.ip-148-113-20.net
- Email Reputation: SPF record present; DMARC configuration absent
- Route Stability: BGP routing marked as unstable (0 route changes in 30-day window)
Temporal Analysis
Observation history contains 11 recorded signals with consistent geolocation attribution to Mumbai, India, and consistent provider identification (OVH Cloud) across all observations. No evidence of persistent malicious behavior or ownership changes was detected.
Relationships and Neighborhood
The IP's relationship graph contains DNS associations to the hostname ns5024995.ip-148-113-20.net. No organizational, certificate, or certificate authority relationships were identified. The /24 subnet (148.113.20.0/24) shows zero abuse density with no neighboring IPs flagged for concern.
Recommended Actions
No immediate firewall or blocking rules are recommended. The IP's low-risk profile, combined with absence of open services and lack of threat indicators, suggests the address does not warrant active mitigation measures at this time. Routine monitoring is advised.
---
*Report generated: [Current Date] | Analyst: IPDebrief Intelligence*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | OVHTECH R&D (INDIA) PRIVATE LIMITED |
| ASN | AS16276 |
| Network Name | SD-YNM-SDAGG-5 |
| CIDR Block | 148.113.20.0/22 |
| RIR | ARIN |
| Country | India |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | ns5024995.ip-148-113-20.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | ns5024995.ip-148-113-20.net |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_6.7p1 OVH-rescue |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 37% | 2 | 5 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 30% | 2 | 3 |
| reputation | 24% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 25% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-08-12 06:11:42 UTC |
| Last Seen | 2026-08-30 17:59:56 UTC |
| Profile Built | 2026-08-30 18:00:45 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 27 |
Full dossier details are available via our API.