# IP Intelligence Briefing: 167.114.139.63
## Executive Summary
IP address 167.114.139.63/32 is a cloud infrastructure endpoint hosted on OVH in Montreal, Canada, with a moderate risk rating (40/100). The IP is associated with Ahrefs domain infrastructure and resolves to proxy-ca000-san63.ahrefs.net. No active malicious campaigns or known attacker indicators were observed.
## Ownership and Infrastructure
- ASN: 16276 (OVH)
- Organization: Dmytro, Ahrefs Pte Ltd
- Network: OVH-CUST-281059679
- Geolocation: Montreal, QC, Canada (with RTT validation discrepancies)
- Infrastructure Type: CloudCompute/Hosting
- Status: Firewalled/No Services (no open ports)
## Threat Assessment
- Risk Score: 40 (Moderate Risk)
- Abuse Confidence: Not calculated
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Blacklist Status: 0 blacklists (1 DNSBL listing out of 8 total)
- Known Campaigns: None
- Campaign Likelihood: None
## Network Context and Neighborhood
The IP resides in subnet 167.114.139.0/24, classified as high abuse density (0.5078). The neighborhood contains:
- 256 total sibling IPs
- 224 active siblings
- 130 threat siblings
- Risk distribution: 84 medium, 16 low, 0 high risk IPs
This indicates the subnet has elevated abuse activity, though the specific IP shows no direct malicious indicators.
## DNS and Services
- Reverse DNS: proxy-ca000-san63.ahrefs.net
- Forward Resolution: Confirmed
- Open Ports: None detected
- TLS Certificates: None
- HTTP Services: None
## Historical Observations
22 observations recorded. Recent signals show:
- Consistent Canadian geolocation attribution
- High abuse density classification maintained
- Domain resolution to ahrefs.net stable
- No new threat indicators detected
## Recommended Actions
Based on current risk profile:
- Block: No immediate blocking required; monitor for changes
- Allow: Permitted traffic
- Monitor: Watch for service openings or risk score escalation
- Firewall Rules: No specific iptables/nftables rules generated
## Intelligence Conclusion
This IP represents a legitimate cloud hosting endpoint in OVH's Montreal infrastructure, associated with Ahrefs proxy services. While the neighborhood shows elevated abuse activity, no direct malicious indicators are present. Continue monitoring for service changes or risk score increases.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059679 |
| CIDR Block | 167.114.139.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca000-san63.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca000-san63.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 31% | 2 | 3 |
| Overall | 22% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-12 09:40:27 UTC |
| Last Seen | 2026-06-27 21:12:47 UTC |
| Profile Built | 2026-06-28 15:18:50 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 26 |
Full dossier details are available via our API.