# IPDEBRIEF INTELLIGENCE BRIEFING
Target: 167.114.139.102/32
Classification: Moderate Risk / Cloud Infrastructure
Date: Current Analysis
---
## EXECUTIVE SUMMARY
IP 167.114.139.102 is a cloud-hosted address registered to OVH-CUST-281059679 under ASN 16276 (Dmytro, Ahrefs Pte Ltd). The address presents moderate risk (score 40) with no active threat indicators but operates within a high-abuse-density subnet (167.114.139.0/24). Geolocation validation anomalies detected.
---
## OWNERSHIP AND NETWORK CLASSIFICATION
- ASN: 16276 (Dmytro, Ahrefs Pte Ltd)
- Organization: OVH-CUST-281059679
- Infrastructure: Cloud compute (OVH hosting provider)
- Country: Canada (CA)
- Region: Quebec (QC)
- City: Montreal
- CIDR Block: 167.114.139.0/24
- Service Purpose: Firewalled / No Services
---
## THREAT INDICATORS ASSESSMENT
- Risk Score: 40 (Moderate)
- Abuse Confidence: Not scored
- Blacklist Status: 0 lists
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Campaign Association: None detected
---
## GEOLOCATION VALIDATION
Status: FLAGGED โ RTT Discrepancy
- Claimed Location: Montreal, QC, CA (45.5063° N, -73.5794° W)
- Observed RTT: 31ms
- Minimum Possible RTT: 112ms (for 5597km distance)
- Validation Result: GEO_PLAUSIBLE = FALSE
- Conclusion: Distance calculation indicates location claim does not match network latency measurements.
---
## DNS AND RESOLUTION DATA
- PTR Hostnames: proxy-ca000-san102.ahrefs.net
- Forward Resolution: proxy-ca000-san102.ahrefs.net
- Domain: ahrefs.net
- Forward Confirmed: No
- Email Authentication: SPF/DMARC not configured
---
## NEIGHBORHOOD ANALYSIS
Subnet: 167.114.139.0/24
- Classification: HIGH ABUSE
- Abuse Density: 0.7188 (71.88%)
- Total Siblings: 256
- Active Siblings: 221
- Threat Siblings: 184
Risk Distribution in /24:
- High Risk: 0 addresses
- Medium Risk: 74 addresses
- Low Risk: 26 addresses
The subnet exhibits elevated abuse density, though the target IP itself lacks specific threat indicators.
---
## OBSERVATION HISTORY
Total Observations: 19 signals
Most Recent: 2026-06-20
Key Historical Signals:
- Network classification consistent: OVH hosting provider
- Geolocation signals show RTT/position violations
- Subnet abuse density classification: high_abuse
- No observed campaigns or correlated malicious activity
---
## SECURITY RECOMMENDATIONS
Risk Score: 40 โ BLOCK RECOMMENDED
Recommended Actions by Platform:
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 167.114.139.102 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 167.114.139.102 drop` |
| nginx | `deny 167.114.139.102;` |
| pfSense | `167.114.139.102/32` |
| Cloudflare WAF | Block with expression: `ip.src eq 167.114.139.102` |
| AWS WAF | Add to deny list: `167.114.139.102/32` |
Rationale: While the IP lacks direct threat indicators, the neighborhood abuse density (71.88%) and moderate risk score warrant defensive blocking. Consider monitoring for any escalation in activity.
---
## INTELLIGENCE ASSESSMENT
This IP appears to be legitimate cloud infrastructure for Ahrefs (SEO tooling company) but operates within an OVH subnet with significant abuse density. The geolocation validation failure suggests potential IP reputation laundering or misconfiguration. No evidence of direct malicious activity, but neighborhood context justifies precautionary blocking.
Recommendation: Block with monitoring. Review for any legitimate business requirements before implementing permanent block.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059679 |
| CIDR Block | 167.114.139.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca000-san102.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca000-san102.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 22% | 1 | 2 |
| geolocation | 33% | 2 | 3 |
| Overall | 22% | 10 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-21 14:56:24 UTC |
| Last Seen | 2026-06-28 13:51:26 UTC |
| Profile Built | 2026-06-29 07:57:56 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 23 |
Full dossier details are available via our API.