IPDebrief

148.113.203.117

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 148.113.203.117/32

Classification: LOW RISK

Date Generated: 2024

---

## Executive Summary

IP address 148.113.203.117 is a low-risk cloud compute endpoint hosted on OVH Hosting infrastructure in Canada. The IP resolves to a VPS hostname and presents standard web server services with no active threat indicators. Neighborhood analysis shows zero abuse density across the /24 subnet.

---

## Network Infrastructure

---

## Risk Assessment

Overall Risk Score: 25/100 (Low Risk)

MetricValue
ReputationLow Risk
Blacklist Count0
Abuse ConfidenceNot flagged
Is Known AttackerNo
Is Tor ExitNo
Is Spam SourceNo

Control Plane Indicators:

---

## Network Services

Open Ports:

Server Fingerprint:

DNS Resolution:

---

## Historical Observations (18 Total)

Recent signal activity observed on 2026-07-31 indicates:

1. Geolocation Signals: Mixed data sources showing CA/US with confidence 0.35-0.75

2. Network Attribution: ASN AS16276 (OVH SAS) detected with confidence 0.75

3. HTTP Probes: Status code 401 (Unauthorized) observed with openresty server signature

4. Ownership: Consistent OVH Hosting attribution with zero ownership changes

Temporal Analysis:

---

## Relationship Analysis

DNS Associations:

Network Associations:

Correlated Entities: 0

Certificate Matches: 0

Banner Matches: 0

---

## Neighborhood Analysis (148.113.203.0/24)

MetricValue
Total Siblings0
Active Siblings0
Threat Siblings0
Abuse Density0
Inherited Risk0

No neighboring IPs detected within the /24 subnet.

---

## Threat Indicators

---

## Recommended Actions

Current Status: No immediate blocking required

Monitoring Recommendations:

Firewall Rules:

---

## Intelligence Narrative

148.113.203.117 operates as a standard web hosting endpoint within OVH's Canadian infrastructure. The IP presents a low-risk profile with no threat indicators detected across multiple data sources. Historical observations show consistent hosting infrastructure behavior with no malicious activity patterns. The associated domain (kaas.am) uses CloudFlare Origin SSL certificates, indicating legitimate web service operations. Neighborhood analysis confirms zero abuse activity within the local subnet. The IP requires only standard monitoring practices and no immediate defensive action.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡จ๐Ÿ‡ฆ Canada
Regionโ€”
CityNew York
Timezoneโ€”
Latitudeโ€”
Longitudeโ€”

๐Ÿข Ownership & Registration

OrganizationOVH Hosting, Inc.
ASNAS16276
Network NameVPS-BHS6
CIDR Block148.113.202.0/23
RIRARIN
CountryCanada
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRvps-ca561b9e.vps.ovh.ca
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnamesvps-ca561b9e.vps.ovh.ca

๐Ÿ” DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierTier 3 โ€” Basic operator with some routing infrastructure
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serveropenresty/1.21.4.1
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
36%
24
routing
13%
11
services
30%
23
ownership
30%
23
reputation
28%
13
geolocation
27%
23
Overall27%1017
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) โ€” 1 contradiction(s)
AttributionModerate (55%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Geo sources disagree on country: US, CA

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-07-30 11:03:13 UTC
Last Seen2026-08-13 00:33:46 UTC
Profile Built2026-08-13 00:39:12 UTC
Data FreshnessLive
Signal Types25
Total Observations26
๐Ÿ” 25 signal types ยท 26 observations collected
This report is generated from 25+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.