# IP INTELLIGENCE BRIEFING
Target: 46.105.208.3/32
Date: 2026-06-19
Classification: MODERATE RISK HOSTING INFRASTRUCTURE
---
## EXECUTIVE SUMMARY
IP 46.105.208.3 is a moderate-risk (score: 40) cloud hosting address operated by OVH Srl (ASN 16276) within Italy. The endpoint hosts a single RDP service on port 3389 and shows minimal malicious indicators. While not flagged as a known attacker or spam source, the IP exhibits a 500km geolocation uncertainty radius and two DNSBL listings across eight total blacklist databases. The IP belongs to a mostly-clean subnet (46.105.208.0/24) with one inherited threat sibling.
---
## INFRASTRUCTURE PROFILE
| Attribute | Value |
|---|---|
| **Owner** | OVH Srl (ASN 16276) |
| **Location** | Italy (IT) - Europe/Rome |
| **Infrastructure** | Cloud Computing / Hosting |
| **DNS** | ip3.ip-46-105-208.eu (Forward confirmed) |
| **Open Ports** | 3389/TCP (RDP) |
| **BGP Prefix** | 46.105.0.0/16 |
| **Route Stability** | False |
| **DNSSEC** | Valid |
---
## THREAT INDICATORS
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0 explicit
- DNSBL Listed: 2/8 total lists
- Campaign Association: None detected
- Threat Persistence: 0 days observed
- Operator Score: 0.2609 (Basic classification)
---
## OBSERVATION HISTORY
Total observations: 23 signals
Recent Activity:
- 2026-06-19: Operator score 0.2609 (Basic), signal confidence 0.60
- 2026-06-14: Geolocation signals confirmed Italy (43.9047, 7.7353), 500km accuracy; RDP service detected
Temporal Analysis:
- Ownership changes: 0
- Threat observation count: 1
- Persistence status: Not persistently malicious
- No correlated campaigns or banner matches identified
---
## NETWORK RELATIONSHIPS
Total Relationships: 53
Key Associations:
- Network: Multiple OVH-DEDICATED-FO relationships
- DNS: ip3.ip-46-105-208.eu
- Network Type: OVH DEDICATED-FO (cloud hosting)
No direct organization or certificate relationships detected beyond network-level associations.
---
## NEIGHBORHOOD ANALYSIS
Subnet: 46.105.208.0/24
Abuse Density: 1
Classification: mostly_clean
Inherited Risk: 2
Total Siblings: 1 (active: 1, threat: 1)
The subnet shows minimal contamination, though one threat sibling exists within the /24 boundary.
---
## RECOMMENDED ACTIONS
Risk Score: 40 (Moderate)
Recommended Status: Monitor or Block (context-dependent)
Firewall Rules Generated:
- iptables: `iptables -A INPUT -s 46.105.208.3 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 46.105.208.3 drop`
- nginx: `deny 46.105.208.3;`
- pfSense: `46.105.208.3/32`
- Cloudflare WAF: Block with expression `ip.src eq 46.105.208.3`
- AWS WAF: Address `46.105.208.3/32`
---
## INTELLIGENCE ASSESSMENT
THREAT LEVEL: LOW-MODERATE
The IP represents a legitimate hosting endpoint with elevated exposure due to open RDP access. The moderate risk score (40) derives primarily from DNSBL listings and route instability rather than active malicious indicators. The IP is not associated with known campaigns or persistent threat activity.
SOC RECOMMENDATION:
- Immediate: No urgent action required
- Monitoring: Track for RDP exploitation attempts
- Mitigation: Consider blocking if RDP access is not required; ensure RDP services are protected with MFA
- Investigation: Correlate with any inbound connection attempts from this IP
CONFIDENCE: Moderate โ Based on 23 historical observations and current network classification data.
---
*Generated by IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | OVH Srl |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | 46.105.0.0/16 |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | ip3.ip-46-105-208.eu |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | ip3.ip-46-105-208.eu |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Not configured |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 3389 | rdp | tcp | โ |
| Closed Ports | 22, 25, 80, 443, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 4 |
| routing | 35% | 2 | 3 |
| services | 12% | 2 | 2 |
| ownership | 30% | 3 | 4 |
| reputation | 27% | 1 | 3 |
| geolocation | 31% | 2 | 3 |
| Overall | 27% | 12 | 19 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-09 11:34:05 UTC |
| Last Seen | 2026-06-27 15:34:42 UTC |
| Profile Built | 2026-06-28 09:40:38 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 30 |
Full dossier details are available via our API.