## IP Intelligence Briefing: 185.113.249.26/32
Classification: Low Risk Infrastructure IP
Summary:
IP 185.113.249.26 is a cloud-hosted infrastructure address operated by OVH (ASN 16276) within the US. The address resolves to ip-185-113-249-26.truehostcloud.com and is associated with the truehostcloud.com domain. Current risk assessment scores 25/100 with a "Low Risk" reputation designation. The IP exhibits cloud compute characteristics with no active services or open ports detected.
Infrastructure Profile:
- Provider: OVH (ASN 16276)
- Infrastructure Type: CloudCompute / Hosting
- Geolocation: United States (US)
- Network Classification: Cloud-based, not CDN/VPN/Proxy
- DNS: PTR resolves to ip-185-113-249-26.truehostcloud.com
- Services: No open ports (firewalled/no services)
- Control Plane: DNSSEC valid, CAA records present
Threat Assessment:
- Risk Score: 25 (Low Risk)
- Threat Indicators: None detected
- Known Campaigns: None correlated
- Blacklist Status: Listed on 1 of 8 DNSBL checks
- Campaign Likelihood: None
- Known Attacker: No
- Tor/Spam Source: No
Historical Signal Analysis:
Twenty-two observations recorded over the monitoring period. The IP has maintained consistent cloud infrastructure classification. Geolocation signals placed the address in US territory with moderate confidence (0.35). DNS associations consistently resolve to truehostcloud.com infrastructure. Operator score remains at Basic level (0.3478). No evidence of escalating malicious behavior or persistent threat activity.
Subnet Analysis (185.113.249.0/24):
- Abuse Density: 0 (Clean subnet classification)
- Threat Siblings: 1
- Active Siblings: 1
- Overall Classification: Mostly Clean
Relationship Graph:
The IP maintains 35 relationships, primarily DNS associations and network-level connections to US-TRUEHOST-20240830. No anomalous cross-network associations detected.
Recommended Actions:
No immediate blocking or firewall actions recommended. The address represents legitimate cloud infrastructure with minimal threat indicators. Standard monitoring procedures apply. No additional firewall rules required based on current risk profile.
Intelligence Assessment:
This IP represents normal cloud hosting infrastructure with no malicious activity observed. The single DNSBL listing appears to be a standard operational record rather than malicious blocking. SOC teams may treat this as benign traffic requiring no special handling.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | lir-us-truehost-1-MNT |
| ASN | AS16276 |
| Network Name | β |
| CIDR Block | β |
| RIR | RIPE |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ip-185-113-249-26.truehostcloud.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ip-185-113-249-26.truehostcloud.com |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 26% | 2 | 2 |
| Overall | 21% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-22 15:18:47 UTC |
| Last Seen | 2026-06-28 19:41:19 UTC |
| Profile Built | 2026-06-29 01:43:48 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.