# IP Intelligence Briefing: 148.113.200.133
## Executive Summary
IP address 148.113.200.133 is hosted on OVH Hosting infrastructure (ASN 16276) within the 148.113.200.0/24 subnet. The IP presents a low-risk profile (risk score: 25) with current classification as a web server in a cloud compute environment. One DNSBL listing was observed with high severity. The IP resolves to mail.inboxifly.com and operates a TLS-secured service (nginx/1.18.0) with Let's Encrypt certificates for gooinbox.com.
## Technical Profile
| Attribute | Value |
|---|---|
| **IP Address** | 148.113.200.133/32 |
| **Risk Score** | 25 (Low Risk) |
| **ASN** | 16276 (OVH Hosting, Inc.) |
| **Network** | 148.113.200.0/24 (VPS-BHS6) |
| **Country** | CA (Canada) |
| **Infrastructure Type** | Cloud Compute |
| **Open Ports** | 80/TCP (HTTP), 443/TCP (HTTPS) |
| **DNS PTR** | mail.inboxifly.com |
| **TLS Subject** | gooinbox.com |
| **Server** | nginx/1.18.0 (Ubuntu) |
## Threat Indicators
- DNSBL Listings: 1 listing detected across 8 total DNSBLs
- Abuse Confidence: Not explicitly scored
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
## Observations & History
Analysis of 28 signal observations reveals the following timeline:
- 2026-08-12: Recent observations indicate DNSBL listings with high severity
- 2026-08-12: DNS records for gooinbox.com observed (SPF/DMARC not detected in recent scan)
- 2026-08-12: HTTP fingerprinting confirms nginx/1.18.0 with HTTP/2 enabled, HSTS not configured
- Temporal Analysis: No persistent malicious behavior detected; threat persistence days: 0
## Network Relationships
| Relationship Type | Target |
|---|---|
| DNS Association | mail.inboxifly.com |
| Same Network | VPS-BHS6 (148.113.200.0/24) |
Multiple DNS and network relationships observed, primarily pointing to mail.inboxifly.com and the VPS-BHS6 network block.
## Neighborhood Analysis
Subnet 148.113.200.0/24 assessment:
- Abuse Density: 1 (mostly clean classification)
- Inherited Risk: 2
- Active Siblings: 1
- Threat Siblings: 1
## Risk Assessment
The IP demonstrates mixed signals:
Risk Factors:
- Single high-severity DNSBL listing
- TLS certificate issued for gooinbox.com (domain not widely recognized in public threat feeds)
- Inherited risk from subnet (1 threat sibling observed)
Mitigating Factors:
- Low overall risk score (25)
- Legitimate hosting provider (OVH)
- No known campaigns or attacker attribution
- Standard web server configuration with TLS encryption
## Recommended Actions
1. Monitor: Continue observing for DNSBL listing updates and campaign correlations
2. Block/Allow Decision: Based on low-risk profile, default allow with monitoring; consider blocking if gooinbox.com is confirmed malicious in additional threat feeds
3. Network Rules: No specific firewall rules generated due to low-risk classification
---
*Intelligence generated by IPDebrief. Data accuracy dependent on signal availability and freshness.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | OVH Hosting, Inc. |
| ASN | AS16276 |
| Network Name | VPS-BHS6 |
| CIDR Block | 148.113.200.0/24 |
| RIR | ARIN |
| Country | Canada |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | mail.inboxifly.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | mail.inboxifly.com |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | 1/2 domains |
| DMARC | 1/2 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
| Domains Checked | 2 domains |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | nginx/1.18.0 (Ubuntu) |
| HTTP Title | โ |
๐ TLS Certificate
CN=gooinbox.com was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.| SANs | gooinbox.comwww.gooinbox.com |
| Valid From | 2026-04-05T02:56:14+00:00 |
| Valid Until | 2026-07-04T02:56:13+00:00 (expired) |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 89 days |
| Serial Number | 052BB3F0A4821784495A196471908623FDCF |
| Thumbprint | 4370BF9382688DFECD0A9533F1DEBCDC61AB21CB |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 32% | 2 | 3 |
| ownership | 30% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 27% | 10 | 17 |
| Data Coherence | Mixed Signals (60%) โ 2 contradiction(s) |
| Attribution | Low (40%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
โ Geo sources disagree on country: US, CA
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-28 22:21:49 UTC |
| Last Seen | 2026-08-12 22:51:02 UTC |
| Profile Built | 2026-08-12 23:03:41 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 27 |
Full dossier details are available via our API.