# IP INTELLIGENCE BRIEFING
IP Address: 167.114.139.71/32
Date: 2026-06-20
Classification: Moderate Risk / Cloud Infrastructure
---
## EXECUTIVE SUMMARY
IP 167.114.139.71 is a cloud computing resource hosted on OVH infrastructure (ASN 16276) associated with Ahrefs Pte Ltd. The IP carries a moderate risk score of 40 and resides within a high-abuse-density subnet (167.114.139.0/24) where 75.8% of sibling IPs have been classified as threats. While the IP itself shows no direct threat indicators, the neighborhood context warrants defensive monitoring.
---
## INFRASTRUCTURE PROFILE
| Attribute | Value |
|---|---|
| **Provider** | OVH (ASN 16276) |
| **Organization** | Dmytro, Ahrefs Pte Ltd |
| **Network Block** | 167.114.139.0/24 |
| **BGP Prefix** | 167.114.128.0/18 |
| **Geolocation** | Montreal, QC, CA |
| **Infrastructure Type** | CloudCompute |
| **Classification** | Hosting / Cloud |
| **Risk Score** | 40 (Moderate) |
DNS Resolution: proxy-ca000-san71.ahrefs.net (ahrefs.net)
---
## THREAT INDICATORS
| Indicator | Status |
|---|---|
| Blacklist Count | 0 |
| Is Tor Exit | No |
| Is Known Attacker | No |
| Is Spam Source | No |
| DNSBL Listed | 1 of 8 lists |
| Abuse Confidence Score | Not available |
| Threat Feeds | None |
Campaign Correlation: No active campaigns detected. No certificate matches or banner matches observed.
---
## NEIGHBORHOOD ANALYSIS
Subnet: 167.114.139.0/24
- Abuse Density: 0.7578 (High Abuse Classification)
- Total Siblings: 256
- Active Siblings: 211
- Threat Siblings: 194
Risk Distribution: 100 medium-risk neighbors, 0 high-risk, 0 low-risk
This subnet demonstrates a significant concentration of abusive activity. Nearly 76% of IPs in the /24 block have been flagged as threats.
---
## OBSERVATION HISTORY
Total Observations: 23 signals recorded
Recent Signals:
- 2026-06-20: Geolocation observation (CA) with confidence 0.18
- 2026-06-15: ASN 16276 allocation confirmation (9,251 days stable)
- 2026-06-15: BGP routing confirmation (as-path: 57866 16276)
- 2026-06-15: Subnet abuse density measurement (0.7578)
Temporal Analysis:
- Ownership Changes: 0
- Threat Persistence Days: 0
- Is Persistently Malicious: False
- Threat Observation Count: 1
The IP has demonstrated stability with no ownership changes and no persistent malicious behavior observed over time.
---
## RELATIONSHIP GRAPH
Primary Associations:
- Network: OVH-CUST-281059679 (25 relationships)
- Hostname: proxy-ca000-san71.ahrefs.net (17 DNS associations)
No additional organizational, certificate, or campaign correlations detected.
---
## GEOLOCATION VALIDATION
Status: ANOMALY DETECTED
- Reported Location: Montreal, QC, CA
- RTT Violation: Observed 27ms RTT < minimum possible 112ms for 5,597km distance
- Probe Count: 5
- GeoConsensus: False
The geolocation data contains inconsistencies suggesting the reported location may be inaccurate.
---
## ACTIONABLE INTELLIGENCE
Risk Assessment
The IP carries moderate risk (40) but operates within a high-abuse-density environment. The association with Ahrefs infrastructure suggests legitimate use cases, but the subnet context elevates defensive considerations.
Recommended Actions
No specific recommendations generated due to lack of direct threat indicators. However, the neighborhood abuse density (0.7578) should inform policy decisions.
Suggested Firewall Rules:
- `iptables -A INPUT -s 167.114.139.71 -j DROP`
- `nft add rule inet filter input ip saddr 167.114.139.71 drop`
- `nginx: deny 167.114.139.71;`
- `pfSense: 167.114.139.71/32`
- `Cloudflare WAF: Block 167.114.139.71 โ IPDebrief risk score 40`
- `AWS WAF: Addresses [167.114.139.71/32], Description: IPDebrief risk 40`
Decision Matrix
| Condition | Recommended Action |
|---|---|
| Direct threat indicators present | BLOCK |
| High-urgency traffic | MONITOR |
| Legitimate business context | ALLOW with logging |
| Unknown traffic | MONITOR for 24 hours |
---
## INTELLIGENCE RECOMMENDATIONS
1. Monitor subnet-level activity given the 75.8% threat density in the /24 block
2. Evaluate Ahrefs association - confirm whether traffic is related to legitimate SEO operations
3. Implement geolocation anomaly detection due to reported location inconsistencies
4. Consider subnet-wide blocking policies if threat activity correlates with observed patterns
5. Maintain logging for forensic correlation during incident investigations
---
Classification: DEFENSIVE INTELLIGENCE
Source: IPDebrief Threat Intelligence Platform
Confidence: MODERATE
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059679 |
| CIDR Block | 167.114.139.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca000-san71.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca000-san71.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 34% | 2 | 3 |
| routing | 27% | 2 | 3 |
| services | 8% | 1 | 1 |
| ownership | 40% | 3 | 5 |
| reputation | 32% | 1 | 3 |
| geolocation | 40% | 2 | 3 |
| Overall | 30% | 11 | 18 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-23 18:29:02 UTC |
| Last Seen | 2026-06-28 22:36:40 UTC |
| Profile Built | 2026-06-29 04:40:49 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 25 |
Full dossier details are available via our API.