# IP INTELLIGENCE BRIEFING: 167.114.139.18
Classification: Moderate Risk | Risk Score: 50/100 | Status: Active
---
## EXECUTIVE SUMMARY
IP address 167.114.139.18 is a residential OVH hosting infrastructure endpoint located in Montreal, Quebec. The IP resolves to hostname proxy-ca000-san18.ahrefs.net, indicating legitimate use by Ahrefs, a web analytics company. However, the IP resides in a high-abuse density subnet (0.7266) with 186 threat-sibling IPs out of 256 total siblings. No direct threat indicators were observed, but the neighborhood risk profile warrants monitoring.
---
## OWNERSHIP & INFRASTRUCTURE
| Attribute | Value |
|---|---|
| **Provider** | OVH |
| **Organization** | Dmytro, Ahrefs Pte Ltd |
| **ASN** | 16276 |
| **CIDR Block** | 167.114.139.0/24 |
| **Geolocation** | Montreal, Quebec, CA |
| **Network Role** | Hosting Provider |
| **Cloud Status** | Yes (CloudCompute) |
The IP has stable ownership and infrastructure classification, with DNS records pointing to legitimate ahrefs.net infrastructure.
---
## THREAT ASSESSMENT
Current Risk Profile:
- Risk Score: 50 (Moderate)
- Abuse Confidence Score: Not available
- Blacklist Count: 0
- Known Attacker: False
- Spam Source: False
- Tor Exit Node: False
- DNSBL Listings: 2 of 8 total lists
Direct Threat Indicators: None observed. No known campaigns, no malicious banner matches, no correlated IPs in threat campaigns.
Geolocation Validation: โ ๏ธ ANOMALY DETECTED
- Reported location: Montreal, CA (56.13°N, -106.35°W)
- Distance from probe origin: 5,597 km
- Observed RTT: 25ms
- Minimum possible RTT for distance: 112ms
- Conclusion: Location data appears spoofed or inconsistent with actual network routing.
---
## NEIGHBORHOOD ANALYSIS (167.114.139.0/24)
| Metric | Value |
|---|---|
| **Abuse Density** | 0.7266 (HIGH) |
| **Classification** | high_abuse |
| **Inherited Risk** | 29 |
| **Total Siblings** | 256 |
| **Active Siblings** | 221 |
| **Threat Siblings** | 186 |
| **Risk Distribution** | 0 High / 55 Medium / 45 Low |
The /24 subnet shows elevated abuse density with 72.66% of IPs exhibiting malicious or suspicious behavior. This is a shared hosting environment where legitimate traffic may be mixed with compromised endpoints.
---
## OBSERVATION HISTORY (23 Total Signals)
The IP has been under observation since at least June 2026. Historical data shows:
- June 20: Subnet classified as "high_abuse" with 0.7266 abuse density
- June 20: Cloud infrastructure classification confirmed
- June 28: Subnet classification fluctuated to "mixed" with 0.4648 abuse density
- June 28: Geolocation data consistently inconsistent with actual RTT
The IP demonstrates persistent hosting infrastructure with fluctuating neighborhood risk classification, suggesting the subnet may contain both legitimate and malicious endpoints.
---
## NETWORK RELATIONSHIPS
All 37 identified relationships map to the same network block (OVH-CUST-281059679). No external correlations to other organizations, certificates, or hostnames beyond the OVH hosting infrastructure.
---
## RECOMMENDED ACTIONS
Based on the moderate risk profile and high-abuse neighborhood, implement the following:
Firewall Rules
iptables:
```bash
iptables -A INPUT -s 167.114.139.18 -j DROP
```
nftables:
```bash
nft add rule inet filter input ip saddr 167.114.139.18 drop
```
nginx:
```nginx
deny 167.114.139.18;
```
pfSense:
```
167.114.139.18/32
```
Cloudflare WAF:
```json
{
"description": "Block 167.114.139.18 โ IPDebrief risk score 50",
"action": "block",
"filter": {
"expression": "ip.src eq 167.114.139.18"
}
}
```
AWS WAF:
```json
{
"Addresses": ["167.114.139.18/32"],
"Description": "IPDebrief risk 50"
}
```
---
## ANALYST NOTES
1. Shared Hosting Risk: The IP operates in a high-abuse OVH shared hosting environment. Even though this specific IP shows no direct threat indicators, traffic from the /24 subnet may include malicious activity from sibling IPs.
2. Legitimate Use Case: The IP resolves to ahrefs.net infrastructure, suggesting legitimate web analytics usage. However, the geolocation inconsistency and neighborhood risk warrant continued monitoring.
3. Recommended Approach: Consider rate-limiting rather than blocking if legitimate Ahrefs traffic is expected. If blocking, monitor for false positives from legitimate Ahrefs operations.
4. Priority: MEDIUM โ Monitor subnet activity and update rules if threat indicators emerge from sibling IPs in the 167.114.139.0/24 block.
---
Report Generated: Current Session
Data Sources: IPDebrief Intelligence Platform
Classification: SOC Intelligence Report
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059679 |
| CIDR Block | 167.114.139.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca000-san18.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca000-san18.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 22% | 1 | 2 |
| geolocation | 39% | 2 | 3 |
| Overall | 23% | 10 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-23 12:22:20 UTC |
| Last Seen | 2026-06-28 21:19:40 UTC |
| Profile Built | 2026-06-29 03:22:56 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 22 |
Full dossier details are available via our API.