## IP Intelligence Briefing: 167.114.139.143
Classification: Moderate Risk (Score: 50/100)
Date: Current Observation Window
Executive Summary
IP 167.114.139.143 is a cloud-hosted infrastructure address associated with OVH's customer network OVH-CUST-281059679. The IP resolves to ahosts.net domain and presents as a proxy/forwarding endpoint. While not actively malicious, the address exhibits moderate risk characteristics with multiple DNSBL listings and is located within a high-abuse-density subnet.
Infrastructure Profile
- ASN/Provider: AS16276 (OVH SA)
- Organization: Dmytro, Ahrefs Pte Ltd
- Geolocation: Montreal, QC, Canada (CA)
- Infrastructure Type: CloudCompute / Hosting
- PTR Hostname: proxy-ca000-san143.ahrefs.net
- DNS Domain: ahrefs.net
Threat Indicators
- DNSBL Status: Listed on 2 of 8 threat feeds
- Abuse Confidence: Moderate (inferred from subnet classification)
- Known Attacker: No
- Tor/Proxy/VPN: Not classified as Tor exit, proxy, or VPN
- Campaign Association: None detected
Risk Context
The IP resides within subnet 167.114.139.0/24, which demonstrates high abuse density (0.6328). The subnet contains 256 total sibling IPs with 222 active endpoints and 162 threat-classified neighbors. This contextual abuse environment elevates the inherent risk profile despite the individual IP not showing active malicious indicators.
Historical Observations
Analysis of 24 signal observations reveals:
- Consistent OVH provider identification across all observations
- Recent threat listings observed with high severity classifications
- No ownership changes detected
- Cloud infrastructure designation persistent
Operational Assessment
The PTR hostname indicates this IP functions as a proxy or forwarding endpoint within the ahrefs.net infrastructure. The forward confirmation status is negative, suggesting DNS resolution inconsistencies. RTT measurements indicate geographic validation challenges (reported distance: 5,597 km from probe location).
Recommended Actions
1. Block at Edge: Implement egress/ingress blocking rules for this IP at perimeter firewalls and WAFs
2. Monitor Activity: If traffic observed, log and analyze for anomalous patterns
3. Subnet Awareness: Be aware that 162 threat-classified IPs exist within the same /24 subnet
4. Allowlist Consideration: If legitimate business use is confirmed, maintain monitoring but no blanket allowlisting recommended
---
Analyst Notes: This IP represents a moderate-risk cloud hosting endpoint with contextual abuse indicators. While not actively malicious, the combination of DNSBL listings and high-density subnet environment warrants defensive blocking or enhanced monitoring depending on organizational policy.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059679 |
| CIDR Block | 167.114.139.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca000-san143.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca000-san143.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 30% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 23% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:51 UTC |
| Last Seen | 2026-06-27 01:23:27 UTC |
| Profile Built | 2026-06-28 00:52:35 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 28 |
Full dossier details are available via our API.