## THREAT INTELLIGENCE BRIEFING
IP Address: 167.114.139.235/32
Date: 2026-06-19
Classification: Moderate Risk (Score: 40/100)
EXECUTIVE SUMMARY
IP 167.114.139.235 is a Canadian-based cloud hosting infrastructure endpoint associated with OVH hosting provider. The IP operates under netname OVH-CUST-281059679 and resolves to ahosted domain proxy-ca000-san235.ahrefs.net. While showing no active malicious indicators, the IP resides within a high-abuse-density subnet (0.7188) with 184 of 220 active sibling IPs flagged as threats.
OWNERSHIP & GEOLOCATION
- Provider: OVH (OVH-CUST-281059679)
- ASN: 16276
- Organization: Dmytro, Ahrefs Pte Ltd
- Location: Montreal, Quebec, Canada (CA)
- Infrastructure: CloudCompute hosting environment
- Registration: ARIN
NETWORK CLASSIFICATION
- Type: Cloud hosting / Firewalled endpoint
- Open Ports: None detected
- DNS: proxy-ca000-san235.ahrefs.net (forward resolution unconfirmed)
- Service: No active services detected
- DNSSEC: Validated
- CAA Records: Present
THREAT INDICATORS
- Abuse Confidence Score: Not calculated
- Blacklist Status: Listed on 1 of 8 DNSBLs
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Active Campaigns: None identified
- Threat Persistence: 0 days (transient)
NEIGHBORHOOD CONTEXT
- Subnet: 167.114.139.0/24
- Abuse Density: 0.7188 (HIGH)
- Subnet Classification: high_abuse
- Threat Siblings: 184 of 220 active IPs flagged as threats
- Inherited Risk Score: 28
OBSERVATION HISTORY
18 signals observed since last measurement. Most recent observation (2026-06-19) confirms:
- Consistent high-abuse classification (0.7188 density)
- Stable ownership with no changes
- No emergence of new threat indicators
RECOMMENDED ACTIONS
Firewall Rule: Block traffic from this IP address
iptables:
```
iptables -A INPUT -s 167.114.139.235 -j DROP
```
nftables:
```
nft add rule inet filter input ip saddr 167.114.139.235 drop
```
Cloudflare WAF:
```json
{
"description": "Block 167.114.139.235 โ IPDebrief risk score 40",
"action": "block",
"filter": {
"expression": "ip.src eq 167.114.139.235"
}
}
```
AWS WAF:
```json
{
"Addresses": ["167.114.139.235/32"],
"Description": "IPDebrief risk 40"
}
```
ANALYST NOTES
This IP represents a cloud hosting endpoint with no services currently exposed. The elevated neighborhood abuse density suggests the subnet is commonly used for legitimate and potentially malicious traffic. The IP's moderate risk score combined with the high-abuse subnet context warrants defensive blocking, particularly given the 1 DNSBL listing. No active threat indicators were observed, but the operational context (cloud hosting in a high-abuse subnet) supports precautionary blocking measures.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059679 |
| CIDR Block | 167.114.139.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca000-san235.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca000-san235.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 39% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 22% | 9 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-13 19:04:00 UTC |
| Last Seen | 2026-06-27 23:43:25 UTC |
| Profile Built | 2026-06-28 17:48:36 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 23 |
Full dossier details are available via our API.