# IP INTELLIGENCE BRIEFING
Target IP: 167.114.139.50/32
Classification: Moderate Risk (Score: 40/100)
Report Date: 2026-06-20
Analyst: IPDebrief Intelligence Platform
---
## EXECUTIVE SUMMARY
The target IP 167.114.139.50 is a cloud-hosted infrastructure endpoint operating within OVH's Montreal, Canada data center. The IP resolves to the ahrefs.net domain with no active services detected. While the individual IP shows moderate risk characteristics, it operates within a subnet exhibiting high abuse density (75.39%), suggesting potential for collateral malicious activity.
---
## OWNERSHIP & INFRASTRUCTURE
Provider: OVH (ASN: 16276)
Organization: Dmytro, Ahrefs Pte Ltd
Network Block: 167.114.139.0/24
Geolocation: Montreal, Quebec, Canada (CA)
Infrastructure Type: CloudCompute / Hosting
Registration RIR: ARIN
The IP is associated with OVH's cloud infrastructure and resolves to a proxy hostname (proxy-ca000-san50.ahrefs.net) under the ahrefs.net domain, indicating legitimate web infrastructure deployment.
---
## THREAT INDICATORS
Threat Status: No Active Threat Indicators
Known Attacker: No
Spam Source: No
Tor Exit Node: No
Blacklist Count: 0
DNSBL Listings: 1 of 8 total lists
Risk Assessment: The IP demonstrates no direct malicious indicators. However, the subnet classification as "high_abuse" with an abuse density score of 0.7539 warrants situational awareness.
---
## NETWORK BEHAVIOR
Service Status: Firewalled / No Services
Open Ports: None detected
TLS Certificate: None
HTTP Title: None
The target exhibits no active service exposure, consistent with backend infrastructure or internal hosting.
---
## SUBNET ANALYSIS: 167.114.139.0/24
Abuse Density: 0.7539 (High)
Subnet Classification: high_abuse
Total IPs: 256
Active Siblings: 211
Threat Siblings: 193
Risk Distribution in Subnet:
- High Risk: 0
- Medium Risk: 99
- Low Risk: 1
The /24 subnet demonstrates elevated abuse activity, with 193 threat-identified siblings. This contextual factor should influence blocking decisions despite the target IP's clean profile.
---
## OBSERVATION HISTORY
Total Observations: 23
Recent Activity: June 15-20, 2026
Threat Persistence: None
Ownership Changes: 0
Historical data indicates stable ownership with no malicious activity patterns detected over the observation period.
---
## RECOMMENDED ACTIONS
Firewall Rules:
- iptables: `iptables -A INPUT -s 167.114.139.50 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 167.114.139.50 drop`
WAF/CDN Integration:
- Cloudflare WAF: Block 167.114.139.50 with risk score 40
- AWS WAF: Block 167.114.139.50/32
Action Priority: LOW-MEDIUM
Justification: While the individual IP shows no direct threat indicators, the high-abuse subnet environment and moderate risk score (40) justify defensive blocking. Monitor for any service activation or behavioral changes.
---
Disclaimer: These intelligence recommendations are probabilistic and should be combined with other security signals before implementing blocking measures.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059679 |
| CIDR Block | 167.114.139.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca000-san50.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca000-san50.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 22% | 1 | 2 |
| geolocation | 33% | 2 | 3 |
| Overall | 22% | 10 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-22 03:08:45 UTC |
| Last Seen | 2026-06-28 17:12:50 UTC |
| Profile Built | 2026-06-29 05:15:31 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 23 |
Full dossier details are available via our API.