IP Intelligence Briefing: 5.135.70.134
Date: 2026-06-16
---
**1. Core Profile**
- Risk Score: 40 (Moderate Risk)
- Provider: OVH Hosting Limited (ASN 16276)
- Location: Dublin 2, Ireland (53.14°N, 7.69°W)
- Network Role: Cloud compute instance (OVH Dedicated)
- Services: Open SSH (port 22) with banner "SSH-2.0-OpenSSH_7.4"
- Threat Indicators: No malicious activity detected in last 30 days.
---
**2. Observation History**
- Latest Activity: June 16, 2026 (moderate confidence, no threats).
- Historical Trends:
- Scanned June 13, 2026, revealing open SSH and no TLS certificates.
- No spam, Tor, or known attacker associations.
- Subnet abuse density: 0.5 (mixed risk).
---
**3. Network Relationships**
- Linked Entities:
- DNS hostname: `ip134.ip-5-135-70.eu` (no malicious indicators).
- Same network: OVH-DEDICATED-FO (AS16276).
- Subnet: `5.135.70.134/24` (1 active sibling IP with risk score 55).
---
**4. Neighborhood Analysis**
- Subnet Abuse: 50% abuse density (1 risky neighbor).
- Neighbors:
- `5.135.70.138` (risk score 55, high risk).
- Recommendation: Monitor subnet for lateral movement risks.
---
**5. Security Actions**
- Firewall Rules:
- iptables: `iptables -A INPUT -s 5.135.70.134 -j DROP`
- Cloudflare WAF: Block IP with description "IPDebrief risk 40".
- AWS WAF: Add `5.135.70.134/32` to rules.
- No Immediate Mitigation Required: No confirmed threats, but subnet risk warrants monitoring.
---
**6. Summary**
The IP is part of a OVH-hosted cloud instance with no direct malicious activity. However, its subnet contains a high-risk neighbor (`5.135.70.138`), suggesting potential lateral movement risks. The open SSH service should be reviewed for unauthorized access. No immediate action is required, but continuous monitoring is advised.
SOC Analyst Notes: Prioritize subnet-level analysis and verify DNS hostname (`ip134.ip-5-135-70.eu`) for additional context.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | OVH Hosting Limited |
| ASN | AS16276 |
| Network Name | OVH-DEDICATED-FO |
| CIDR Block | 5.135.70.128/25 |
| RIR | RIPE |
| Country | IE |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | ip134.ip-5-135-70.eu |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | ip134.ip-5-135-70.eu |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Not configured |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_7.4 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 42% | 2 | 5 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 30% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 27% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-06-04 18:52:16 UTC |
| Last Seen | 2026-06-26 14:31:51 UTC |
| Profile Built | 2026-06-21 12:02:12 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 26 |
Full dossier details are available via our API.