IP Intelligence Briefing: 167.114.139.217
Date: 2026-06-13
---
**1. Core Profile**
- Risk Score: 50 (Moderate Risk)
- Ownership:
- ASN: 16276 (OVH)
- Organization: Dmytro, Ahrefs Pte Ltd
- Netname: OVH-CUST-281059679
- Geolocation:
- Country: Canada (QC, Montreal)
- Accuracy Radius: 3,000 km
- Network Role:
- CloudCompute (OVH)
- Hosting: Yes
- Subnet: 167.114.139.0/24
---
**2. Threat Indicators**
- No Direct Malicious Activity:
- No indicators of spam, attacker, or Tor exit nodes.
- Zero threat feeds or campaigns linked.
- DNS & Services:
- PTR hostname: `proxy-ca000-san217.ahrefs.net`
- No open ports or TLS certificates detected.
---
**3. Network & Subnet Analysis**
- Subnet Abuse Density:
- 62.55% of sibling IPs (251 total) flagged as high-risk.
- 157 active threat siblings in the 167.114.139.0/24 subnet.
- Risk Inheritance:
- Inherited risk score: 25 (moderate) due to subnet context.
---
**4. Observation History**
- Recent Signals (2026-06-13):
- DNSSEC validation: Valid
- CAA records: Present
- Low confidence in geolocation (3000 km accuracy).
- No persistent malicious activity observed.
---
**5. Relationships & Connections**
- Linked Entities:
- Subnet: OVH-CUST-281059679
- Hostname: `proxy-ca000-san217.ahrefs.net` (ahrefs.net domain).
- No Known Campaigns or Correlated IPs.
---
**6. Recommended Actions**
- Firewall Blocking Rules:
- iptables: `iptables -A INPUT -s 167.114.139.217 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 167.114.139.217 drop`
- Cloudflare WAF: Block IP with rule `ip.src eq 167.114.139.217`
- Monitor Subnet:
- High abuse density in 167.114.139.0/24 suggests broader subnet monitoring.
- Investigate neighboring IPs (e.g., 167.114.139.0โ167.114.139.255) for potential threats.
---
**7. Summary**
The IP 167.114.139.217 is associated with a legitimate hosting provider (OVH) and appears to belong to Ahrefs, a known cybersecurity company. While the IP itself shows no direct malicious activity, its subnet (167.114.139.0/24) has a high abuse density (62.55%), with 157 threat siblings. SOC teams should:
1. Block the IP using provided firewall rules.
2. Monitor the entire subnet for anomalous activity.
3. Verify geolocation accuracy and check for potential spoofing.
Note: The IPโs risk score (50) and inherited subnet risk suggest caution, but no immediate action is required unless further indicators emerge.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059679 |
| CIDR Block | 167.114.139.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca000-san217.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca000-san217.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 30% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 23% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:51 UTC |
| Last Seen | 2026-06-27 01:28:10 UTC |
| Profile Built | 2026-06-28 00:40:02 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 28 |
Full dossier details are available via our API.