# IP INTELLIGENCE BRIEFING: 167.114.139.76
Classification: Moderate Risk (Score: 50/100)
Date: Current Intelligence Update
---
## EXECUTIVE SUMMARY
IP 167.114.139.76 is a cloud-hosted infrastructure endpoint owned by Ahrefs Pte Ltd (OVH customer network) located in Montreal, Canada. The IP presents moderate risk with no active threat indicators but operates within a high-abuse-density subnet. No open services detected; IP is firewalled with no active ports.
---
## OWNERSHIP & NETWORK CLASSIFICATION
| Attribute | Value |
|---|---|
| **ASN** | 16276 (OVH SAS) |
| **Organization** | Dmytro, Ahrefs Pte Ltd |
| **Network** | OVH-CUST-281059679 |
| **CIDR Block** | 167.114.139.0/24 |
| **Infrastructure** | CloudCompute / Hosting |
| **Provider** | OVH |
Geolocation: Montreal, QC, Canada (CA)
Note: Geo validation anomaly detectedβRTT measurements indicate 5,597km distance from probe origin, suggesting reported geolocation may be inaccurate.
---
## THREAT INDICATORS
Current Risk Profile:
- Risk Score: 50/100 (Moderate)
- Abuse Confidence: Not scored
- Blacklist Count: 0
- Known Campaigns: None identified
- Tor Exit/Proxy: Negative
- Known Attacker: Negative
Control Plane Observations:
- DNSBL Listings: 2 out of 8 total lists
- Route Stability: NOT stable
- Operator Score: 0.2174 (Minimal)
---
## NETWORK BEHAVIOR
Service Status: Firewalled / No Services Active
DNS Resolution: proxy-ca000-san76.ahrefs.net (ahrefs.net domain)
Email Authentication: SPF/DMARC not configured
TLS/HTTP: No certificates, no active HTTP services
---
## NEIGHBORHOOD ANALYSIS
Subnet: 167.114.139.0/24
Abuse Density: 0.7188 (High Abuse Classification)
Active Siblings: 221 / 256 total IPs
Threat Siblings: 184 (83% of active IPs flagged as threats)
Risk Distribution in Subnet:
- High Risk: 0
- Medium Risk: 74 (74%)
- Low Risk: 26 (26%)
Notable Neighbor IPs:
- 167.114.139.0, .1, .3: Risk Score 40
- 167.114.139.2, .4: Risk Score 25
---
## OBSERVATION HISTORY
Total Signals: 19 observations tracked
Latest Signal: 2026-06-28T13:53:03
Key Historical Signals:
- 2026-06-20: High abuse density classification (0.7188)
- 2026-06-20: Operator score 0.2174 (Minimal)
- 2026-06-20: CloudCompute infrastructure confirmed
- 2026-06-28: Continued cloud/hosting classification
Temporal Analysis:
- Ownership Changes: 0
- Threat Persistence Days: 0
- Persistently Malicious: No
---
## RECOMMENDED ACTIONS
Firewall/IPS Rules:
- Monitor inbound/outbound traffic; no active services require blocking
- Consider rate-limiting given high-abuse subnet context
- Implement geo-IP restrictions if Montreal geolocation is inaccurate
Detection Signatures:
- Monitor DNS queries to ahrefs.net (proxy-ca000-san76.ahrefs.net)
- Flag connections from subnet 167.114.139.0/24 with elevated threat scores
- Alert on outbound connections from this subnet
Investigation Recommendations:
- Correlate with other IPs in OVH-CUST-281059679 network
- Review DNSBL listings for specific reputation concerns
- Assess if Ahrefs infrastructure is being leveraged for proxying
---
ASSESSMENT: This IP represents cloud-hosted infrastructure with moderate risk. While the IP itself shows no active malicious indicators, the high abuse density of its subnet warrants monitoring. No immediate blocking required, but traffic correlation and subnet-level analysis recommended for enhanced threat visibility.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059679 |
| CIDR Block | 167.114.139.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca000-san76.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca000-san76.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 39% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 25% | 9 | 13 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-21 14:56:25 UTC |
| Last Seen | 2026-06-28 13:53:10 UTC |
| Profile Built | 2026-06-29 07:59:06 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 24 |
Full dossier details are available via our API.