# IP Intelligence Briefing: 185.2.49.125/32
Classification: Moderate Risk | Date of Assessment: 2026-08-12
---
## Executive Summary
IP 185.2.49.125 is a cloud-hosted infrastructure address operated by OVH (ASN 16276) with a risk score of 50/100. The IP is classified as hosting infrastructure located in Mumbai, India, within the AR-Solution network block (185.2.49.0/24). Current threat indicators are minimal, but the moderate risk classification warrants monitoring due to cloud infrastructure nature and 2 DNSBL listings.
---
## Risk Profile
| Metric | Value |
|---|---|
| **Risk Score** | 50 (Moderate Risk) |
| **Infrastructure Type** | CloudCompute / Hosting |
| **Country** | India (Maharashtra, Mumbai) |
| **ASN** | 16276 |
| **Organization** | AR-Solution |
| **Provider** | OVH |
| **DNSBL Listings** | 2 of 8 total lists |
---
## Threat Indicators
- Not identified as known attacker, Tor exit node, or spam source
- No active threat indicators in current assessment
- 2 DNSBL listings present across 8 total lists
- Route stability flagged as false (potential routing anomalies)
---
## Network Context
Subnet Analysis (185.2.49.0/24):
- Abuse Density: 0
- Classification: Clean
- Total Siblings: 2
- Threat Siblings: 0
- Neighbor IP 185.2.49.118 shows low risk score (25/100)
The /24 subnet demonstrates minimal abuse activity with no correlated threats among neighboring IPs.
---
## Historical Observations
Analysis of 21 signal observations reveals the following temporal patterns:
- Provider consistently identified as OVH hosting infrastructure
- Geolocation signals point to Mumbai, India with 28% confidence
- Operator scores remain minimal (0.1304)
- Multiple blacklist listings observed in recent cycles
- No evidence of persistent malicious behavior
---
## Network Services
- Open Ports: None detected (firewalled/no services)
- Reverse DNS: Not configured
- Forward Resolution: Not confirmed
- HTTP Services: No active web services detected
---
## Recommended Actions
1. Monitor IP for changes in DNSBL listings or service activation
2. Block if outbound connections are observed from internal assets (hosting infrastructure may be compromised)
3. Log all traffic for forensic analysis if connection attempts are detected
4. No immediate block required if inbound-only traffic is confirmed
---
## Conclusion
IP 185.2.49.125 presents a moderate risk profile typical of cloud hosting infrastructure. The absence of active threat indicators, combined with a clean subnet neighborhood, suggests limited immediate threat. Standard monitoring and logging practices are recommended, with escalation if service activation or blacklist growth occurs.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | hk-larus-1-mnt |
| ASN | AS16276 |
| Network Name | AR-Solution |
| CIDR Block | 185.2.49.0/24 |
| RIR | RIPE |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 15% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 23% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-29 04:30:09 UTC |
| Last Seen | 2026-08-12 23:10:56 UTC |
| Profile Built | 2026-08-12 23:18:10 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 21 |
Full dossier details are available via our API.