Threat Intelligence Briefing: IP 167.114.139.119/32
IP Address: 167.114.139.119/32
Data Collection Period: [Specify Date Range]
Tools Used: Passive DNS, WHOIS, Geolocation, Network Traffic Analysis, Historical Threat Intelligence Databases
Summary:
IP address 167.114.139.119/32 is a single, specific IP address within a larger network block associated with [ISP Name]. The analysis of available data provides the following insights:
1. Ownership and Registration:
- The IP is registered to [Company/Organization Name], which is identified as a [Type of Entity] based on WHOIS data.
- The registration details indicate the IP is used for [Primary Purpose], such as [e.g., web hosting, cloud services, etc.].
2. Geolocation:
- The IP is geolocated to [Country/City], aligning with the registered organization's physical location.
3. Network Traffic Analysis:
- Passive network traffic analysis shows that the IP has been involved in [Type of Traffic, e.g., web traffic, email traffic].
- The traffic patterns indicate normal operational activity consistent with [Primary Purpose].
4. Observation History:
- Historical data reveals no significant anomalies or malicious activities associated with this IP address.
- There have been [Number] reported incidents involving this IP, primarily categorized as [Type of Incident, e.g., false positives, benign anomalies].
5. Relationships and Associations:
- The IP has communicated with known [Good/Bad] IPs, indicating a [benign/malicious] relationship.
- No direct associations with known malicious domains or IPs were observed.
6. Neighborhood Data:
- Neighboring IP addresses within the same /24 block have been associated with [Types of Activity, e.g., similar legitimate services, unrelated malicious activities].
- No evidence suggests that the immediate network environment poses a threat.
Actionable Insights:
- Monitoring: Continue to monitor traffic from this IP for any deviations from established baselines, focusing on unexpected traffic volumes or destinations.
- Threat Hunting: Cross-reference with internal threat intelligence feeds to ensure no emerging threats are associated with this IP.
- Incident Response Preparedness: Maintain readiness to investigate any alerts related to this IP, particularly if traffic patterns change significantly.
Conclusion:
IP 167.114.139.119/32 is currently associated with legitimate activities as per the gathered data. No immediate threats are identified, but ongoing monitoring is recommended to detect any potential shifts in behavior.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059679 |
| CIDR Block | 167.114.139.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca000-san119.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca000-san119.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 22% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-09 11:33:39 UTC |
| Last Seen | 2026-06-27 15:22:43 UTC |
| Profile Built | 2026-06-28 09:27:59 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 27 |
Full dossier details are available via our API.