IPDebrief

148.113.209.179

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING

Target: 148.113.209.179/32

Classification: Low Risk VPS Hosting Infrastructure

Generated: Current

Status: ACTIVE

---

## EXECUTIVE SUMMARY

IP 148.113.209.179 is a low-risk (Score: 25) VPS infrastructure node operated by OVH Hosting, Inc. (ASN 16276). The address is registered in Canada (CA) within cloud compute infrastructure. While the IP maintains a clean overall reputation, it exhibits one DNSBL listing and shows historical DNS blacklist activity with high-severity classifications. The neighborhood contains one threat sibling, warranting contextual awareness.

---

## INFRASTRUCTURE PROFILE

AttributeValue
**ASN**16276 (OVH Hosting, Inc.)
**Organization**OVH Hosting, Inc.
**Country**Canada (CA)
**Infrastructure Type**Cloud Compute / VPS
**CIDR Block**148.113.128.0/17 (BGP Origin)
**Route Stability**False

---

## NETWORK SERVICES & FINGERPRINTING

PortProtocolServiceStatus
80TCPHTTPOPEN
443TCPHTTPSOPEN
22TCPSSHOPEN

Server Banner: nginx/1.26.0 (Ubuntu)

TLS Certificate: Let's Encrypt (Issuer: CN=E8, O=Let's Encrypt, C=US)

Subject CN: bahastore.tn

PTR Record: vps-7b96cc0f.vps.ovh.ca

HTTP Response: Status code 303 (Redirect)

HTTP Version: 1.1

---

## THREAT INDICATORS

IndicatorStatusDetails
**Known Attacker**CLEARNo indicators
**Spam Source**CLEARNo indicators
**Tor Exit Node**CLEARFalse
**Blacklist Count**CLEAR0
**DNSBL Listed**ACTIVE1 of 8 total lists
**Abuse Confidence Score**NULLNot applicable

Historical DNS Blacklisting: 26 observations recorded. Most recent observation (2026-06-19) shows 8 total DNSBL listings with 2 listed at high severity.

---

## NEIGHBORHOOD ANALYSIS

MetricValue
**Subnet**148.113.209.0/24
**Abuse Density**0 (Clean)
**Total Siblings**1
**Active Siblings**0
**Threat Siblings**1

Classification: mostly_clean

Inherited Risk: 2

---

## OBSERVATION HISTORY (26 RECORDS)

Latest Activity: 2026-06-19T14:48:16 UTC

Key Signals:

---

## RELATIONSHIP GRAPH

Primary Associations (36 total records):

---

## RECOMMENDED ACTIONS

Current Risk Score: 25 (Low Risk)

Recommended Security Actions: None automatically generated due to low risk profile.

Manual Considerations:

1. Monitor DNSBL listing activity for potential reputation degradation

2. Investigate the one threat sibling in the 148.113.209.0/24 subnet

3. Standard VPS traffic monitoring applies (SSH, HTTP, HTTPS)

4. No immediate blocking recommended; allowlist for legitimate OVH traffic

---

## CONCLUSION

IP 148.113.209.179 represents a standard OVH-hosted VPS with low-risk characteristics. The single DNSBL listing and historical blacklist activity require monitoring but do not indicate active malicious behavior. The presence of one threat sibling in the immediate subnet suggests potential co-location of malicious activity, which should be tracked for correlation. Routine SOC monitoring and traffic analysis are sufficient; no aggressive blocking measures recommended at this time.

Classification: LOW RISK

Priority: STANDARD

Action: MONITOR

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡จ๐Ÿ‡ฆ Canada
Regionโ€”
Cityโ€”
Timezoneโ€”
Latitude43.63
Longitude-79.37

๐Ÿข Ownership & Registration

OrganizationOVH Hosting, Inc.
ASNAS16276
Network Nameโ€”
CIDR Blockโ€”
RIRARIN
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRvps-7b96cc0f.vps.ovh.ca
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnamesvps-7b96cc0f.vps.ovh.ca

๐Ÿ” DNS Hygiene

Hygiene Score80% (Excellent)
SPF2/3 domains
DMARC1/3 domains
FCrDNSVerified
DNSSECValid
CAANot configured
Domains Checked3 domains

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeWeb Server
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
443httpstcpโ€”
22sshtcp
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
Servernginx/1.26.0 (Ubuntu)
HTTP Titleโ€”
SSH VersionSSH-2.0-OpenSSH_9.7p1 Ubuntu-7ubuntu4.3

๐Ÿ” TLS Certificate

๐Ÿ”’
CN=bahastore.tn
Issued by CN=E8, O=Let's Encrypt, C=US
Self-signed: No
SANsbahastore.tn
Valid From2026-04-24T01:47:17+00:00
Valid Until2026-07-23T01:47:16+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha384ECDSA
Validity Period89 days
Serial Number0697CDEE43C1628CC4D5ACA38CF36A564441
ThumbprintDC7897E1881CD8A0BF30FEF40A8194CCA24344EA

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
35%
24
routing
13%
11
services
28%
23
ownership
20%
23
reputation
28%
13
geolocation
35%
23
Overall27%1017
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) โ€” 1 contradiction(s)
AttributionModerate (55%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Claimed geolocation contradicts RTT physics measurement

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-10 04:11:31 UTC
Last Seen2026-06-27 16:53:38 UTC
Profile Built2026-06-28 10:59:14 UTC
Data FreshnessLive
Signal Types23
Total Observations30
๐Ÿ” 23 signal types ยท 30 observations collected
This report is generated from 23+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.