IPDebrief

5.135.4.149

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 5.135.4.149

Classification: LOW RISK

Date: 2026-06-19

Prepared for: SOC Operations

---

## Executive Summary

IP 5.135.4.149 is a low-risk residential cloud infrastructure endpoint hosted on OVH cloud network. The IP demonstrates no active threat indicators and maintains a stable reputation profile. While the subnet contains one threat sibling, this IP itself shows no malicious behavior. No immediate defensive actions required.

---

## Profile Analysis

Reputation Score: 25/100 (Low Risk)

Network Classification: CloudCompute / Web Server

ASN: 16276 (OVH SAS)

Geolocation: Roubaix, Hauts-de-France, France (FR)

Infrastructure Type: Cloud Hosting

Network Role:

Services:

DNS Analysis:

- ip149.ip-5-135-4.eu

- alpha-test.securinfor.fr

- eva-inv.securinfor.fr

- eva16-dev.securinfor.fr

- eva16-test.securinfor.fr

TLS Certificate:

---

## Threat Indicators

Active Threats: None

Control Plane:

---

## Observation History

Total Observations: 24

Observation Period: 2026-06-15 to 2026-06-19

Threat Persistence: 0 days

Status Change: No significant degradation observed

Recent Signals:

---

## Relationships Graph

Total Relationships: 44

Primary Associations:

Related Entities: No high-risk organizational or campaign associations identified.

---

## Neighborhood Analysis

Subnet: 5.135.4.0/24

Abuse Density: 1 (Low)

Classification: mostly_clean

Total Siblings: 1

Active Siblings: 1

Threat Siblings: 1

Risk Distribution:

The subnet shows minimal abuse activity, with one threat sibling detected in the broader /24 range. No correlation to known malicious campaigns.

---

## Recommended Actions

Current Status: No immediate action required

Risk Score: 25 (Low)

Provider Score: 0

Authority Score: 0

Firewall Rules: None generated (risk below threshold)

WAF Recommendations: None required

Monitoring Suggestions:

---

## Conclusion

IP 5.135.4.149 is a legitimate OVH cloud hosting endpoint with normal web server activity. The five hosted domains suggest test/development infrastructure for securinfor.fr. No defensive blocking is warranted. Standard network monitoring protocols apply. If the IP appears in incident traffic, investigate at the application layer rather than network level.

---

*End of Briefing*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ซ๐Ÿ‡ท France
RegionHauts-de-France
CityRoubaix
TimezoneEurope/Paris
Latitude48.86
Longitude2.34

๐Ÿข Ownership & Registration

OrganizationOVH Technical Contact
ASNAS16276
Network Nameโ€”
CIDR Blockโ€”
RIRRIPE
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRip149.ip-5-135-4.eu
Forward ConfirmedYes โ€” FCrDNS verified
Hosted Domainip149.ip-5-135-4.eu
Hosted Domainalpha-test.securinfor.fr
Hosted Domaineva-inv.securinfor.fr
Hosted Domaineva16-dev.securinfor.fr
Hosted Domaineva16-test.securinfor.fr
Forward Hostnamesip149.ip-5-135-4.eu

๐Ÿ” DNS Hygiene

Hygiene Score80% (Excellent)
SPF1/2 domains
DMARC2/2 domains
FCrDNSVerified
DNSSECValid
CAANot configured
Domains Checked2 domains

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeWeb Server
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
443httpstcpโ€”
Closed Ports22, 25, 3389, 8080, 8443 (2 open / 7 scanned)
Servernginx/1.24.0 (Ubuntu)
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
CN=alpha-test.securinfor.fr
Issued by CN=E8, O=Let's Encrypt, C=US
Self-signed: No
SANsalpha-test.securinfor.fr
Valid From2026-04-15T12:15:37+00:00
Valid Until2026-07-14T12:15:36+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha384ECDSA
Validity Period89 days
Serial Number061ED817F7BB4FC05E24DA1730641250AE81
ThumbprintCD053884D3BF24EB7D9A5DC66DE0225AEA907363

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
29%
24
routing
13%
11
services
26%
23
ownership
24%
23
reputation
26%
13
geolocation
33%
23
Overall25%1017
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-21 02:16:50 UTC
Last Seen2026-06-28 13:01:24 UTC
Profile Built2026-06-29 07:06:42 UTC
Data FreshnessLive
Signal Types24
Total Observations28
๐Ÿ” 24 signal types ยท 28 observations collected
This report is generated from 24+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.