IP Intelligence Briefing: 167.114.139.173
Date: 2026-06-13
---
**1. Core Profile**
- Risk Score: 40 (Moderate Risk)
- Ownership: Owned by OVH (AS16276) under Dmytro, Ahrefs Pte Ltd.
- Geolocation: Montreal, Canada (CA). GeoPlausible flag is false, suggesting location inconsistencies.
- Network Role: Cloud compute instance (OVH) with hosting and firewalled classification.
- Threat Indicators: No direct malicious activity detected (no abuse confidence, spam, or known attacker flags).
---
**2. Observation History**
- 21 observations over 30 days:
- Geolocation: Confirmed as Montreal, Canada (low confidence, 0.18).
- Subnet Abuse: High abuse density (72.66%) in 167.114.139.0/24, classified as high_abuse.
- Control Plane: DNSSEC valid, CAA record present, but listed in 1 DNSBL (out of 8).
- Stability: Route stability is false; IP shows inconsistent routing behavior.
---
**3. Network Relationships**
- Linked Entities:
- Subnet: OVH-CUST-281059679 (167.114.139.0/24).
- No direct links to domains, organizations, or certificates.
- Subnet Analysis:
- 256 IPs in subnet, 186 flagged as threats.
- Abuse Density: 72.66% (high risk).
---
**4. Neighborhood Analysis**
- Subnet: 167.114.139.0/24.
- Risk Distribution:
- 100 IPs in subnet (100% coverage).
- 99 IPs rated medium risk (score 40), 1 IP rated low risk.
- Abuse Density: 72.66% (high risk).
---
**5. Key Findings**
- Cloud Hosting: IP is part of OVH's cloud infrastructure, likely a virtual machine or hosted server.
- Subnet Risk: High abuse density in the subnet suggests potential for compromised hosts or malicious activity within the network.
- Geolocation Concerns: Montreal, Canada location is flagged as non-plausible (RTT mismatch), possibly indicating misconfigured DNS or spoofing.
- No Direct Threats: IP itself shows no malicious indicators but is part of a high-risk subnet.
---
**6. Recommendations**
1. Monitor Subnet: Investigate the 167.114.139.0/24 subnet for unusual activity (e.g., outbound connections, DNS anomalies).
2. Verify Geolocation: Confirm IP location accuracy, as the geoPlausible flag is false.
3. Cloud Security: Review OVH-hosted assets for potential breaches or misconfigurations.
4. Network Segmentation: Consider isolating high-risk subnets to limit lateral movement.
5. DNS Validation: Ensure DNSSEC and CAA records are correctly configured to mitigate spoofing risks.
---
Source: IPDebrief Threat Intelligence Platform.
Note: This IP is part of a high-risk subnet but shows no direct malicious activity. Further investigation into the subnet's behavior is advised.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059679 |
| CIDR Block | 167.114.139.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca000-san173.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca000-san173.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 30% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 23% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:51 UTC |
| Last Seen | 2026-06-27 01:25:48 UTC |
| Profile Built | 2026-06-28 00:40:02 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 28 |
Full dossier details are available via our API.