# IP INTELLIGENCE BRIEFING
Target: 5.196.105.61/32
Classification: LOW RISK / MONITORING
Date: Current Analysis
Analyst: IPDebrief Intelligence Team
---
## EXECUTIVE SUMMARY
IP 5.196.105.61 is a cloud computing host operated by OVH (ASN 16276) with a low risk profile (score: 25/100). The address is associated with the OVH_478016941 network block and resolves to hostname ip61.ip-5-196-105.eu. No active threat indicators, campaigns, or persistent malicious behavior detected. Single SSH port (22/tcp) is open. Recommended action: Standard monitoring with no blocking required.
---
## OWNERSHIP & INFRASTRUCTURE
- Provider: OVH (ASN 16276, RIR: RIPE)
- Organization: Adak Server
- CIDR Block: 5.196.105.48/28
- Infrastructure Type: Cloud Compute
- Network Role: Single-Service Host
- Geolocation: France (FR) - Regional inference available
- DNS: ip61.ip-5-196-105.eu (forward resolution confirmed)
---
## RISK ASSESSMENT
| Metric | Value | Severity |
|---|---|---|
| Overall Risk Score | 25 | LOW |
| Reputation | Low Risk | - |
| Abuse Confidence | Not applicable | - |
| Blacklist Count | 0 | CLEAN |
| Threat Indicators | None | - |
| Known Campaigns | None | - |
Control Plane Metrics:
- Operator Score: 0.2609 (Basic)
- Route Stability: False
- DNSSEC Valid: True
- DNSBL Listings: 1 of 8 total lists
---
## NETWORK ACTIVITY
- Open Ports: 22/tcp (SSH - OpenSSH_8.9p1 Ubuntu-3ubuntu0.15)
- TLS Certificate: Not present
- HTTP Services: None detected
- Anycast: No
- IPv6: No
---
## THREAT INTELLIGENCE
- Threat Feeds: No active indicators
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Malicious Campaign Likelihood: None
- Persistently Malicious: False
---
## OBSERVATION HISTORY
Total observations: 23 signals collected
Key Historical Signals:
- 2026-06-21: Geolocation inference (France, 500km accuracy)
- 2026-06-16: Subnet abuse density analysis (classification: mostly_clean, abuse density: 1)
- 2026-06-16: Ownership stability assessment (0 changes detected)
- 2026-06-16: Threat classification (not attacker, not spam source, 0 blacklist entries)
Temporal Indicators:
- Ownership Changes: 0
- Threat Persistence Days: 0
- Threat Observation Count: 1
---
## RELATIONSHIP ANALYSIS
- Network Associations: Multiple same-network relationships to OVH_478016941
- DNS Associations: Consistent resolution to ip61.ip-5-196-105.eu
- Related Entities: No external organization or certificate associations identified
---
## NEIGHBORHOOD ANALYSIS
Subnet: 5.196.105.61/24
- Abuse Density: 0 (from neighbor analysis)
- Classification: Mostly Clean
- Active Siblings: 1
- Threat Siblings: 0
- Inherited Risk: 2 (low)
---
## SOC ACTION RECOMMENDATIONS
IMMEDIATE ACTIONS
1. Monitoring: Continue passive observation with standard SOC logging
2. Allow/Block: No blocking recommended - risk profile supports standard allow
3. Traffic Analysis: SSH traffic from this port may warrant traffic pattern review if anomalous
FIREWALL CONSIDERATIONS
- No specific firewall rules recommended based on current risk profile
- Standard SSH port filtering per organizational policy if applicable
MONITORING TRIGGERS
Alert on:
- New service/port openings
- Geolocation changes
- Blacklist additions
- Emergence of threat indicators
---
## CONCLUSION
5.196.105.61 represents a standard cloud computing host with no observable malicious activity. The low risk score (25/100), absence of threat indicators, and clean neighborhood profile indicate this IP is operating within normal parameters. No immediate defensive action required beyond routine monitoring.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Adak Server |
| ASN | AS16276 |
| Network Name | OVH_478016941 |
| CIDR Block | 5.196.105.48/28 |
| RIR | RIPE |
| Country | FR |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | ip61.ip-5-196-105.eu |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | ip61.ip-5-196-105.eu |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Not configured |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 26% | 2 | 2 |
| Overall | 23% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-06-01 23:54:50 UTC |
| Last Seen | 2026-06-29 10:17:42 UTC |
| Profile Built | 2026-06-29 16:20:07 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 24 |
Full dossier details are available via our API.