# INTELLIGENCE BRIEFING: IP 148.113.201.65/32
Classification: Low Risk Cloud Infrastructure
Date: 2024
Intel Source: IPDebrief
---
## EXECUTIVE SUMMARY
IP address 148.113.201.65 resolves to a low-risk (Score: 25) cloud computing resource hosted by OVH Hosting, Inc. (ASN 16276). The IP demonstrates minimal threat indicators, no active open ports, and no known malicious activity. However, geolocation data validation failures and neighborhood-level threat presence warrant contextual awareness for security operations.
---
## INFRASTRUCTURE PROFILE
Ownership & Network:
- ASN: 16276 (OVH Hosting, Inc.)
- Infrastructure Type: CloudCompute / Hosting
- BGP Prefix: 148.113.128.0/17
- Route Stability: False (isRouteStable)
- Control Plane Operator Score: 0.2609 (Basic)
Geolocation:
- Country: Canada (CA)
- Accuracy Radius: 3000 km
- Data Validation: GeoPlausible = False
- RTT Anomaly: 27ms observed vs. 121.6ms minimum possible for 6082km distance
DNS Resolution:
- PTR Hostname: mail.veterinaria-x-correos.abrdns.com
- Forward Resolution: Confirmed
- Domain: abrdns.com
- Email Authentication: SPF/DMARC absent
- TXT Record Count: 0
---
## THREAT ASSESSMENT
Risk Indicators:
- Overall Risk Score: 25 (Low Risk)
- Abuse Confidence Score: Not applicable
- Blacklist Count: 0
- Tor Exit Node: False
- Known Attacker: False
- Spam Source: False
- Known Campaigns: None
Service Exposure:
- Open Ports: None detected
- TLS Certificate: None
- HTTP Banner: None
- Service Classification: Firewalled / No Services
Threat Persistence:
- Threat Observation Count: 1
- Is Persistently Malicious: False
- Threat Persistence Days: 0
---
## NEIGHBORHOOD ANALYSIS
Subnet: 148.113.201.65/24
- Abuse Density: 1
- Classification: Mostly Clean
- Inherited Risk: 5
- Total Siblings: 2
- Active Siblings: 2
- Threat Siblings: 2
Neighbor Risk Distribution:
- High Risk: 0
- Medium Risk: 1 (148.113.201.25, Risk Score: 50, Authority Score: 60)
- Low Risk: 0
Assessment: The /24 subnet shows elevated neighborhood-level risk with 2 identified threat siblings and 1 medium-risk neighbor. This suggests the subnet may host mixed-use infrastructure.
---
## RELATIONSHIP GRAPH
Identified Associations:
- DNS: mail.veterinaria-x-correos.abrdns.com (multiple associations)
- Network: VPS-BHS6 (same network classification)
- Network Type: Cloud/VPS infrastructure
Total relationships identified: 49
---
## OBSERVATION HISTORY
Total Observations: 23 signals recorded
Recent Activity (June 2026):
- 2026-06-28: Hostname resolution to mail.veterinaria-x-correos.abrdns.com (Confidence: 50%)
- 2026-06-20: Port scanning activity detected (Confidence: 70%)
- 2026-06-20: Subnet classification "mostly_clean" with abuse density 1 (Confidence: 40%)
- 2026-06-20: Ownership stability tracking (Confidence: 85%)
- 2026-06-20: BGP prefix 148.113.128.0/17, no attacker status (Confidence: 20%)
Historical Trends: No persistent malicious behavior detected. Single threat observation recorded with zero persistence days.
---
## SECURITY ACTIONS & RECOMMENDATIONS
Risk Score: 25 (Low Risk)
Provider: OVH
Recommended Actions: None at this time. The IP demonstrates low-risk characteristics with no active service exposure or known malicious indicators.
Firewall Rules: Not generated (risk score below threshold)
Monitoring Considerations:
- Monitor neighborhood activity due to 2 threat siblings in subnet
- Validate geolocation data accuracy (RTT anomaly detected)
- Track DNS resolution patterns for mail.veterinaria-x-correos.abrdns.com
---
## INTELLIGENCE NOTES
1. Cloud Infrastructure Context: This is a hosted cloud computing resource with no active services or open ports. The "Firewalled / No Services" designation indicates the IP may be a control plane or management address.
2. Geolocation Uncertainty: Significant RTT violation suggests the Canadian geolocation may be inaccurate. Actual origin location remains unconfirmed.
3. Neighborhood Context: The /24 subnet contains 2 threat-identified siblings with a medium-risk neighbor (148.113.201.25). While this IP remains clean, proximity to known threats warrants awareness.
4. Email Reputation: DNS records indicate association with veterinary email domain (abrdns.com) but lack email authentication (SPF/DMARC). No email reputation scoring available.
5. Threat Profile: No active threat indicators. Empty threat indicators array, zero blacklist listings, and no known campaign associations.
---
BRIEFING PREPARED: SOC Threat Intelligence Team
DATA FRESHNESS: Current as of analysis timestamp
ACTION REQUIRED: Monitor for neighborhood activity changes; no immediate action required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | OVH Hosting, Inc. |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | mail.veterinaria-x-correos.abrdns.com |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | mail.veterinaria-x-correos.abrdns.com |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 25% | 10 | 16 |
| Data Coherence | Mixed Signals (60%) โ 2 contradiction(s) |
| Attribution | Very Low (20%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
โ Geo sources disagree on country: US, CA
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-21 20:59:19 UTC |
| Last Seen | 2026-06-28 15:22:58 UTC |
| Profile Built | 2026-06-29 03:27:31 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 24 |
Full dossier details are available via our API.