IPDebrief

149.56.15.83

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING: 149.56.15.83/32

## EXECUTIVE SUMMARY

IP address 149.56.15.83 was classified as Moderate Risk with an IPDebrief risk score of 40. The IP is hosted on OVH Hosting, Inc. infrastructure in Montreal, Quebec, Canada. No active threat indicators were detected, though the IP appears on 2 of 8 DNSBL lists. The IP is currently firewalled with no open services detected.

---

## NETWORK AND OWNERSHIP PROFILE

---

## THREAT ASSESSMENT

IndicatorStatus
Risk Score40 (Moderate)
Blacklist Count2
DNSBL Lists2 of 8
Known AttackerNo
Spam SourceNo
Tor Exit NodeNo
Known CampaignsNone

The IP scored 40 on the overall risk scale. Provider and authority scores were 0. The control plane operator score was 0.2609 (Basic). RPKI state and IRR consistency were not determinable. The IP is listed on 2 DNSBL entries out of 8 total checks.

---

## BEHAVIORAL AND HISTORICAL ANALYSIS

Observation Period: 15 signals recorded

Recent Activity: All observations occurred on 2026-07-31

Key Historical Findings:

Anomalies Detected:

---

## INFRASTRUCTURE AND NETWORK CONTEXT

- Honeypot Hits: 0

- Enumeration Strikes: 0

- WAF Violations: None recorded

Relationship Graph: 4 associations identified

Neighborhood Analysis: Subnet 149.56.15.0/24 showed:

---

## RECOMMENDED ACTIONS

Based on the risk profile, the following firewall rules were generated:

PlatformRule
iptables`iptables -A INPUT -s 149.56.15.83 -j DROP`
nftables`nft add rule inet filter input ip saddr 149.56.15.83 drop`
nginx`deny 149.56.15.83;`
pfSense`149.56.15.83/32`
Cloudflare WAFBlock IP 149.56.15.83 (risk score 40)
AWS WAFAdd 149.56.15.83/32 to blacklist

Note: These recommendations are probabilistic and should be combined with other signals before taking action.

---

## ANALYST NOTES

The IP exhibits characteristics of a standard cloud hosting environment with no active malicious services. The moderate risk score (40) stems primarily from DNSBL listings and geolocation validation anomalies rather than active threat indicators. The RTT violation suggests either inaccurate geolocation data or routing anomalies. No immediate threat mitigation required beyond standard cloud provider monitoring. Continuous monitoring recommended due to hosting provider infrastructure type.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡จ๐Ÿ‡ฆ Canada
RegionQuebec
CityMontreal
Timezoneโ€”
Latitude45.51
Longitude-73.59

๐Ÿข Ownership & Registration

OrganizationOVH Hosting, Inc.
ASNAS16276
Network NameOVH-VPS-149-56-12-NET
CIDR Block149.56.12.0/22
RIRARIN
CountryCanada
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR83.ip-149-56-15.net
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnames83.ip-149-56-15.net

๐Ÿ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeWeb Server
Network TierTier 3 โ€” Basic operator with some routing infrastructure
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
443httpstcpโ€”
22sshtcp
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
ServerApache/2.2.0 (Fedora)
HTTP Titleโ€”
SSH VersionSSH-2.0-OpenSSH_7.4p1 Debian-10+deb9u7

๐Ÿ” TLS Certificate

A self-signed certificate was detected. This is common for development servers, internal services, or IoT devices.
โš ๏ธ
CN=a07f8155de6a
Issued by CN=a07f8155de6a
Self-signed: Yes
SANsNone
Valid From2019-03-20T19:22:54+00:00
Valid Until2029-03-17T19:22:54+00:00
TLS ProtocolTls12
Cipher SuiteTLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period3650 days
Serial Number00BEF567EDA749CD4B
ThumbprintE420D831CDEBF8C8FE8169C03E7C63FA6B12F232

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
42%
23
routing
13%
11
services
30%
23
ownership
27%
23
reputation
17%
11
geolocation
27%
23
Overall26%1014
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) โ€” 1 contradiction(s)
AttributionModerate (55%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Claimed geolocation contradicts RTT physics measurement

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-07-30 23:19:56 UTC
Last Seen2026-08-13 01:07:27 UTC
Profile Built2026-08-13 01:18:28 UTC
Data FreshnessLive
Signal Types21
Total Observations22
๐Ÿ” 21 signal types ยท 22 observations collected
This report is generated from 21+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.