## IP INTELLIGENCE BRIEFING: 167.114.139.69/32
Classification: Moderate Risk | Risk Score: 40
Ownership and Infrastructure
The IP belongs to OVH-CUST-281059679, assigned to Ahrefs Pte Ltd (ASN 16276, OVH network). The address is hosted on cloud computing infrastructure with a stated purpose of "Firewalled / No Services." DNS resolution points to proxy-ca000-san69.ahrefs.net, indicating association with the ahrefs.net domain ecosystem.
Geolocation Validation
Reported location: Montreal, QC, CA. Geolocation implausibility detected: Round-trip time (RTT) measurements indicate 24ms latency, while the minimum physically possible RTT for 5,597.4km distance is 111.9ms. This discrepancy suggests reported geographic coordinates do not match observed network characteristics.
Threat Profile
- Abuse Confidence: Not elevated
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Presence: Listed on 1 of 8 DNSBLs
- Campaign Correlation: None identified
- Persistence: Not persistently malicious
Neighborhood Context
The /24 subnet (167.114.139.0/24) shows high abuse density (0.7422):
- Total siblings: 256
- Active siblings: 207
- Threat siblings: 190
- Inherited risk score: 29
This indicates the IP resides within a heavily utilized OVH hosting environment with significant abuse activity among neighboring addresses.
Temporal Signals
21 observations recorded. Recent signals from 2026-06-15 confirm high_abuse subnet classification with 0.7422 abuse density. Ownership stability shows 0 ownership changes, suggesting consistent infrastructure assignment.
Recommended Actions
Given the moderate risk profile (40) and subnet abuse characteristics, defensive posture may be warranted:
Firewall Rules:
- `iptables -A INPUT -s 167.114.139.69 -j DROP`
- `nft add rule inet filter input ip saddr 167.114.139.69 drop`
- `nginx: deny 167.114.139.69;`
- Cloudflare WAF: Block IP with risk score 40
- AWS WAF: Add 167.114.139.69/32 to block list
Assessment Summary
IP 167.114.139.69 represents moderate risk (40) within a high-abuse subnet (0.7422). While no active threat indicators are present, the neighborhood context suggests elevated risk posture. No open services detected; infrastructure appears firewalled. Geographic validation anomalies warrant monitoring. Recommend correlating with other signals before implementing blocking measures.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059679 |
| CIDR Block | 167.114.139.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca000-san69.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca000-san69.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 23% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-17 15:12:03 UTC |
| Last Seen | 2026-06-28 05:10:52 UTC |
| Profile Built | 2026-06-28 23:15:17 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 25 |
Full dossier details are available via our API.