IP Intelligence Briefing: 167.114.139.145
Date: 2026-06-13
---
**1. Core Profile**
- Risk Score: Moderate (50/100)
- Network Role: CloudCompute (OVH)
- Geolocation: Montreal, Canada (geoPlausible: False)
- ASN: 16276 (OVH-CUST-281059679)
- Ownership: Ahrefs Pte Ltd (OVH customer)
- Threat Indicators: None detected
---
**2. Observation History**
- Recent Activity (2026-06-13):
- Confirmed as a cloud-hosted IP (OVH infrastructure).
- Geo validation violation: RTT (27ms) inconsistent with 5,597km distance (minimum possible RTT: 111.9ms).
- No DNS or TLS anomalies detected.
- Historical Trends:
- No persistent threat signals (threatObservationCount: 0).
- Stability score: Minimal (0.2174).
---
**3. Relationships & Network Context**
- Linked Entities:
- Subnet: 167.114.139.0/24 (OVH network).
- DNS: PTR hostname `proxy-ca000-san145.ahrefs.net` (linked to ahrefs.net).
- Subnet Risk:
- Abuse density: 0.5219 (high_abuse classification).
- 76/100 neighbors flagged as medium-risk.
- 131/251 siblings associated with threats.
---
**4. Threat & Security Context**
- DNS Security:
- DNSSEC validated, but 2/8 DNSBL lists flagged (potential spam/abuse).
- No email authentication (SPF/DKIM/DMARC) detected.
- Network Behavior:
- No open ports or TLS certificates observed.
- No correlation with known campaigns or malicious domains.
---
**5. Recommendations**
1. Monitor Subnet Activity:
- The 167.114.139.0/24 subnet has high abuse density. Investigate traffic patterns and isolate suspicious siblings.
2. Validate Geolocation:
- The IPโs RTT inconsistency suggests potential spoofing or misconfigured routing. Cross-check with alternative geolocation sources.
3. DNS Security:
- Ensure the `ahrefs.net` domain is not compromised (e.g., check for DNS hijacking or misconfigured records).
4. Network Segmentation:
- Consider isolating this cloud-hosted IP from internal networks due to its mixed-risk subnet.
---
Conclusion:
The IP is part of a cloud infrastructure (OVH) with no direct threat indicators, but its subnet exhibits elevated abuse density. While the IP itself is not malicious, the network context warrants closer monitoring for potential lateral movement or compromised neighbors.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059679 |
| CIDR Block | 167.114.139.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca000-san145.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca000-san145.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 21% | 2 | 2 |
| reputation | 32% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 24% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:51 UTC |
| Last Seen | 2026-06-27 01:23:47 UTC |
| Profile Built | 2026-06-28 00:47:58 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 29 |
Full dossier details are available via our API.