# IP INTELLIGENCE BRIEFING
Target IP: 167.114.139.185/32
Classification: Cloud Infrastructure / DNSBL Listed
Report Generated: 2026-06-16
---
## EXECUTIVE SUMMARY
IP 167.114.139.185 is a cloud compute address hosted by OVH in Montreal, Canada, resolving to the Ahrefs.net proxy infrastructure. The IP carries an overall risk score of 25 (Low Risk) but is listed on one DNSBL with high severity. No active malicious campaigns or open services detected. The entire /24 subnet (100 IPs) shows uniform medium-risk profiles (score: 40), suggesting standardized hosting infrastructure rather than targeted abuse.
---
## PROFILE DETAILS
Risk Assessment
- Overall Risk Score: 25 (Low Risk)
- Provider Score: 0 (Neutral)
- Authority Score: 0 (Neutral)
- Stability Score: 0 (Neutral)
Network Classification
- Provider: OVH (ASN: 16276)
- Infrastructure Type: CloudCompute
- Location: Montreal, Quebec, Canada (45.51°N, -73.58°W)
- Cloud Status: Confirmed Cloud (not CDN, VPN, Proxy, or Tor exit node)
- Hosting: Yes (ISP/Hosting provider)
DNS Resolution
- PTR Record: proxy-ca000-san185.ahrefs.net
- Domain: ahrefs.net
- Forward Resolution: Confirmed (1 hostname)
- Email Auth: SPF: No | DMARC: No
---
## THREAT INDICATORS
Current Threat Posture
- Abuse Confidence Score: Not available
- Blacklist Status: 1 DNSBL listing (High severity)
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Active Threats: None detected
Campaign Correlation
- Known Campaigns: None
- Certificate Matches: 0
- Correlated IPs: 0
---
## OBSERVATION HISTORY
Total Observations: 11 signals captured
Key Historical Signals:
- 2026-06-16 15:43:48: Control plane assessment (Operator score: 0.2174, Label: Minimal)
- 2026-06-16 15:43:41: Geolocation confirmed (Montreal, Quebec, Canada)
- 2026-06-16 15:42:47: Cloud/hosting classification confirmed (OVH)
- 2026-06-16 15:41:51: DNSBL listing detected (8 total lists, 1 active listing with high severity)
Temporal Analysis: No persistent malicious behavior detected. Ownership changes: 0. Threat observation count: 0.
---
## NETWORK RELATIONSHIPS
DNS Associations: proxy-ca000-san185.ahrefs.net (3 relationship entries)
Control Plane Data:
- BGP Prefix: 167.114.128.0/18
- Route Stability: False
- MoAS Status: False
- DNSSEC: Valid
- CAAA Records: Present
---
## NEIGHBORHOOD ANALYSIS
Subnet: 167.114.139.0/24
- Total Siblings: 100 IPs
- Abuse Density: 0
- Risk Distribution:
- High Risk: 0
- Medium Risk: 100 (all neighbors)
- Low Risk: 0
Neighborhood Risk Score: 40 (Medium) โ All IPs in subnet show uniform risk profiles, indicating standardized infrastructure rather than targeted abuse.
---
## SERVICES & PORTS
Open Ports: None detected
TLS Certificate: None
HTTP Title: None
Banner: None
Status: Firewalled / No Services
---
## RECOMMENDED ACTIONS
Current Risk: Low (Score: 25)
Recommended Actions:
- No immediate firewall rules generated (risk score below threshold)
- Monitor DNSBL listing status for changes
- No blocking recommended; standard monitoring advised
- Verify Ahrefs.net service legitimacy if receiving traffic from this IP
Firewall Rules: None required (low-risk profile)
---
## SOC ANALYST NOTES
This IP represents legitimate cloud infrastructure hosting for Ahrefs.net proxy services. The single DNSBL listing warrants awareness but does not indicate active malicious activity. The uniform medium-risk profile across the entire /24 subnet is typical of large cloud hosting providers and does not suggest coordinated abuse.
Priority: LOW
Action: Monitor only
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059679 |
| CIDR Block | 167.114.139.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca000-san185.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca000-san185.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 17% | 1 | 1 |
| routing | 17% | 1 | 1 |
| services | 17% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 17% | 1 | 1 |
| geolocation | 17% | 1 | 1 |
| Overall | 14% | 5 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-06-09 02:09:36 UTC |
| Last Seen | 2026-06-21 15:38:41 UTC |
| Profile Built | 2026-06-21 15:42:08 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 18 |
Full dossier details are available via our API.