# IP INTELLIGENCE BRIEFING: 149.56.15.83/32
## EXECUTIVE SUMMARY
IP address 149.56.15.83 was classified as Moderate Risk with an IPDebrief risk score of 40. The IP is hosted on OVH Hosting, Inc. infrastructure in Montreal, Quebec, Canada. No active threat indicators were detected, though the IP appears on 2 of 8 DNSBL lists. The IP is currently firewalled with no open services detected.
---
## NETWORK AND OWNERSHIP PROFILE
- IP Address: 149.56.15.83/32
- ASN: 16276 (OVH Hosting, Inc.)
- Organization: OVH Hosting, Inc.
- CIDR Block: 149.56.12.0/22
- Network Name: OVH-VPS-149-56-12-NET
- Geolocation: Montreal, Quebec, Canada (CA)
- Coordinates: 45.5075°N, -73.5887°W
- Infrastructure Type: Cloud Compute / Hosting Provider
- DNS PTR Record: 83.ip-149-56-15.net
---
## THREAT ASSESSMENT
| Indicator | Status |
|---|---|
| Risk Score | 40 (Moderate) |
| Blacklist Count | 2 |
| DNSBL Lists | 2 of 8 |
| Known Attacker | No |
| Spam Source | No |
| Tor Exit Node | No |
| Known Campaigns | None |
The IP scored 40 on the overall risk scale. Provider and authority scores were 0. The control plane operator score was 0.2609 (Basic). RPKI state and IRR consistency were not determinable. The IP is listed on 2 DNSBL entries out of 8 total checks.
---
## BEHAVIORAL AND HISTORICAL ANALYSIS
Observation Period: 15 signals recorded
Recent Activity: All observations occurred on 2026-07-31
Key Historical Findings:
- Geolocation Consensus: True (1 source)
- Network Role: Cloud compute environment (confirmed)
- Threat Persistence: 0 days (not persistently malicious)
- Threat Observation Count: 0
- Ownership Changes: 0
Anomalies Detected:
- RTT Violation: Observed RTT of 31โ36ms violates minimum expected RTT of 112ms for the claimed 5,598km distance from probe location. Geo validation flagged as implausible.
- Geo Plausible: False (distance discrepancy detected)
---
## INFRASTRUCTURE AND NETWORK CONTEXT
- Services: No open ports detected (Firewalled / No Services)
- TLS Certificate: None
- HTTP Banner: None
- Fingerprint: No distinctive web server signatures
- Email Reputation: Not scored
- Traceroute: 0 hops recorded
- Behavioral Indicators:
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: None recorded
Relationship Graph: 4 associations identified
- DNS Association: 83.ip-149-56-15.net (duplicate entries)
- Same Network: OVH-VPS-149-56-12-NET (duplicate entries)
Neighborhood Analysis: Subnet 149.56.15.0/24 showed:
- Neighbor Count: 0
- Abuse Density: 0
- Risk Distribution: High (0), Medium (0), Low (0)
- Active Threat Siblings: 0
---
## RECOMMENDED ACTIONS
Based on the risk profile, the following firewall rules were generated:
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 149.56.15.83 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 149.56.15.83 drop` |
| nginx | `deny 149.56.15.83;` |
| pfSense | `149.56.15.83/32` |
| Cloudflare WAF | Block IP 149.56.15.83 (risk score 40) |
| AWS WAF | Add 149.56.15.83/32 to blacklist |
Note: These recommendations are probabilistic and should be combined with other signals before taking action.
---
## ANALYST NOTES
The IP exhibits characteristics of a standard cloud hosting environment with no active malicious services. The moderate risk score (40) stems primarily from DNSBL listings and geolocation validation anomalies rather than active threat indicators. The RTT violation suggests either inaccurate geolocation data or routing anomalies. No immediate threat mitigation required beyond standard cloud provider monitoring. Continuous monitoring recommended due to hosting provider infrastructure type.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | OVH Hosting, Inc. |
| ASN | AS16276 |
| Network Name | OVH-VPS-149-56-12-NET |
| CIDR Block | 149.56.12.0/22 |
| RIR | ARIN |
| Country | Canada |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 83.ip-149-56-15.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | 83.ip-149-56-15.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | Apache/2.2.0 (Fedora) |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_7.4p1 Debian-10+deb9u7 |
๐ TLS Certificate
| SANs | None |
| Valid From | 2019-03-20T19:22:54+00:00 |
| Valid Until | 2029-03-17T19:22:54+00:00 |
| TLS Protocol | Tls12 |
| Cipher Suite | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 3650 days |
| Serial Number | 00BEF567EDA749CD4B |
| Thumbprint | E420D831CDEBF8C8FE8169C03E7C63FA6B12F232 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 42% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 1 |
| geolocation | 27% | 2 | 3 |
| Overall | 26% | 10 | 14 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-30 23:19:56 UTC |
| Last Seen | 2026-08-13 01:07:27 UTC |
| Profile Built | 2026-08-13 01:18:28 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.