# IP Intelligence Briefing: 167.114.139.66
## Executive Summary
IP address 167.114.139.66 is a moderate-risk residential proxy endpoint hosted on OVH infrastructure in Montreal, Canada. The IP resolves to the ahrefs.net domain and exhibits high-abuse characteristics inherited from its /24 subnet. While no active threat indicators are present, the subnet's elevated abuse density warrants monitoring.
## Technical Profile
Risk Assessment: 40/100 (Moderate Risk)
Network Classification: CloudCompute, Hosting environment
Geolocation: Montreal, QC, Canada (CA) โ *Note: Geolocation validation flagged with 5597km distance discrepancy from probe measurements*
Provider: OVH (ASN 16276)
Organization: Dmytro, Ahrefs Pte Ltd
CIDR Block: 167.114.139.0/24
## DNS & Service Analysis
- PTR Hostnames: proxy-ca000-san66.ahrefs.net
- Forward Resolution: 1 hostname confirmed
- Domain Association: ahrefs.net
- Open Ports: None detected (Firewalled / No Services)
- TLS Certificate: None
- Email Authentication: No SPF or DMARC records configured
## Threat Indicators
- Blacklist Status: 0/0 lists
- DNSBL Listings: 1/8 total lists
- Known Attacker: False
- Spam Source: False
- Tor Exit Node: False
- Active Campaigns: None detected
- Operator Score: 0.2174 (Minimal)
## Subnet Neighborhood Analysis
Subnet: 167.114.139.0/24
Abuse Density: 0.7188 (High Abuse)
Classification: HIGH_ABUSE
Sibling Statistics:
- Total IPs: 256
- Active: 221
- Threat-Associated: 184
- Inherited Risk Score: 28
Risk Distribution Across /24: 75% Medium Risk, 25% Low Risk (no high-risk neighbors detected)
## Historical Observations
Analysis of 20 historical observations indicates consistent infrastructure classification with provider (OVH) and network role (CloudCompute, Hosting) remaining stable. No significant changes in threat profile or ownership observed. Threat observation count: 0. IP is not classified as persistently malicious.
## Relationship Graph
The IP maintains 39 documented relationships, primarily with the same network identifier (OVH-CUST-281059679). No cross-organizational or certificate-based relationships detected.
## Recommended Actions
No specific firewall or mitigation rules were generated. The IP presents moderate risk with no active malicious indicators. Recommended monitoring approach:
1. Monitor subnet-level abuse patterns (184 threat siblings in /24)
2. Verify geolocation consistency given distance anomalies
3. Flag for review if DNSBL listings increase or threat indicators emerge
4. Consider blocking if traffic patterns indicate abuse originating from the subnet
---
*Generated: 2026-06-28*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059679 |
| CIDR Block | 167.114.139.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca000-san66.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca000-san66.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 22% | 1 | 2 |
| geolocation | 39% | 2 | 3 |
| Overall | 23% | 10 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-19 09:36:38 UTC |
| Last Seen | 2026-06-28 08:44:33 UTC |
| Profile Built | 2026-06-29 02:48:49 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 24 |
Full dossier details are available via our API.