# IP Intelligence Briefing: 167.114.139.197/32
## Executive Summary
The IP address 167.114.139.197 was analyzed on 2026-06-20. The address resolved to a moderate-risk infrastructure endpoint operated by OVH in Montreal, Canada, associated with the Ahrefs domain. No active malicious indicators were detected, but the subnet exhibits elevated abuse density.
## Technical Profile
- IP Address: 167.114.139.197
- Risk Score: 40 (Moderate Risk)
- ASN: 16276 (OVH SAS)
- Organization: Dmytro, Ahrefs Pte Ltd
- Network Block: 167.114.139.0/24
- Location: Montreal, Quebec, Canada (CA)
- Infrastructure Type: Cloud Compute / Hosting
DNS Resolution
The IP resolves to proxy-ca000-san197.ahrefs.net with forward confirmation. The domain ahrefs.net has CAA records configured. No email authentication (SPF/DMARC) was observed for the resolved host.
Network Services
No open ports were detected. The endpoint is classified as "Firewalled / No Services" with no TLS certificates, HTTP responses, or service banners observed during probing.
## Threat Indicators
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Blacklist Count: 0
- Known Campaigns: None detected
Control Plane Data
- BGP Prefix: 167.114.128.0/18
- Route Stability: False
- DNSBL Listed: 1 of 8 total lists
- DNSSEC Valid: Yes
- RPKI State: Not evaluated
## Neighborhood Analysis
The /24 subnet 167.114.139.0/24 was classified as "high_abuse" with an abuse density of 0.7266. Of 256 total sibling addresses, 221 were active and 186 were classified as threat siblings, resulting in an inherited risk score of 29 for the subnet.
## Observation History
19 historical observations were recorded. The most recent signals (2026-06-20) confirmed:
- Geographic location: Canada (CA)
- Provider classification: OVH, Cloud Compute, Hosting
- Subnet classification: high_abuse with 0.7266 abuse density
## Threat Assessment
The endpoint presents moderate risk primarily due to subnet-level abuse characteristics rather than endpoint-specific malicious activity. The IP is associated with a legitimate service provider (OVH) and resolves to a known Ahrefs infrastructure hostname. No evidence of active exploitation or campaign activity was observed.
## Recommendations
Given the moderate risk classification and subnet-level abuse density, the following actions are recommended:
1. Monitor: Implement traffic monitoring for outbound connections from this IP to the ahrefs.net domain
2. Block Assessment: Consider blocking at the subnet level if the organization cannot distinguish between legitimate Ahrefs services and potential abuse
3. Threat Feeds: Monitor DNSBL lists for any new listings against this IP or subnet
4. Baseline: Establish baseline traffic patterns to detect anomalies from this IP address
Classification: Moderate Risk
Threat Level: Low (No active indicators)
Action Priority: Monitor
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059679 |
| CIDR Block | 167.114.139.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca000-san197.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca000-san197.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 19% | 2 | 2 |
| reputation | 32% | 1 | 3 |
| geolocation | 34% | 2 | 3 |
| Overall | 23% | 9 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-25 06:41:23 UTC |
| Last Seen | 2026-06-29 01:14:37 UTC |
| Profile Built | 2026-06-29 07:17:06 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.