# INTELLIGENCE BRIEFING: 167.114.139.152/32
## Executive Summary
IP 167.114.139.152 is a Moderate Risk (score: 40/100) hosting IP assigned to OVH cloud infrastructure (ASN 16276), registered to "Dmytro, Ahrefs Pte Ltd." The address resolves to Ahrefs.net proxy infrastructure (proxy-ca000-san152.ahrefs.net) and is located in Montreal, Canada. The IP operates within a high-abuse density subnet (167.114.139.0/24) with 186 threat-sibling IPs out of 221 active siblings, indicating elevated neighborhood-level risk.
---
## Ownership & Infrastructure
- Organization: Dmytro, Ahrefs Pte Ltd
- ASN: 16276 (OVH)
- CIDR Block: 167.114.139.0/24
- Infrastructure Type: CloudCompute (OVH hosting provider)
- Classification: Cloud hosting infrastructure with firewalled services (no open ports detected)
---
## Geolocation & Network Positioning
- Country: Canada (CA)
- Region: Quebec (QC)
- City: Montreal
- BGP Prefix: 167.114.128.0/18
- Route Stability: Unstable (route changes detected in past 30 days)
- DNSSEC: Validated
---
## Threat Indicators
- Abuse Confidence: No specific threat indicators flagged
- Blacklist Status: Listed on 1 DNSBL out of 8 total checks
- Campaign Matching: No known campaign correlations
- Known Attacker Status: Not flagged as known attacker
- Spam Source: Not identified as spam source
- Tor Exit Node: No
---
## Subnet Neighborhood Analysis
The /24 subnet (167.114.139.0/24) demonstrates significant abuse activity:
- Abuse Density Score: 0.7266 (High)
- Total Siblings: 256
- Active Siblings: 221
- Threat Siblings: 186
- Subnet Classification: high_abuse
- Inherited Risk: 29
Neighbor distribution shows 62 medium-risk and 38 low-risk IPs in the immediate vicinity, with no high-risk siblings detected beyond the target IP.
---
## DNS & Reputation Profile
- PTR Record: proxy-ca000-san152.ahrefs.net
- Forward Resolution: Confirmed (1 hostname)
- Domain: ahrefs.net
- Email Authentication: No SPF or DMARC records present
- Operator Score: 0.2174 (Minimal)
---
## Temporal Observations
- Observation Count: 20 signals over monitoring period
- Ownership Changes: 0
- Threat Persistence Days: 0
- Most Recent Activity: June 20, 2026
- Persistence Assessment: Not persistently malicious
---
## Recommended Actions
Based on the risk profile and neighborhood context:
1. Monitoring: Continue monitoring for activity patterns; subnet-level risk warrants ongoing observation
2. Firewall Rules: Consider rate limiting if traffic patterns align with abusive behavior
3. Threat Correlation: Monitor for lateral movement within the 167.114.139.0/24 subnet given high abuse density
4. DNS Policy: Review DNSBL listing status; 1 of 8 blacklist checks returned positive
---
## Intelligence Conclusion
IP 167.114.139.152 represents moderate risk hosting infrastructure operating within a high-abuse-density OVH subnet. While the target IP itself shows no direct threat indicators, the surrounding neighborhood (186 threat siblings) suggests the subnet may be utilized for various abusive activities. SOC teams should monitor traffic patterns and consider subnet-level context in incident response decisions. No immediate blocking action recommended unless specific threat indicators emerge.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059679 |
| CIDR Block | 167.114.139.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca000-san152.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca000-san152.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 21% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-22 03:08:45 UTC |
| Last Seen | 2026-06-28 17:12:34 UTC |
| Profile Built | 2026-06-29 05:15:31 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 23 |
Full dossier details are available via our API.