# IP INTELLIGENCE BRIEFING: 5.196.136.132
## Executive Summary
Risk Assessment: LOW RISK (Score: 25/100)
IP 5.196.136.132 is a cloud-hosted address in the OVH SAS infrastructure located in Roubaix, France. No active malicious indicators detected. Suitable for standard monitoring with no immediate blocking required.
---
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **Organization** | OVH SAS (ASN: AS16276) |
| **Network Block** | 5.196.136.128/28 |
| **Geolocation** | Roubaix, France (48.8582°N, 2.3387°E) |
| **Infrastructure Type** | Cloud Compute (Hosting Provider) |
| **DNS Hostname** | ip132.ip-5-196-136.eu |
---
## Threat Intelligence Indicators
Malicious Activity: NONE DETECTED
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Blacklist Count: 0
- Abuse Confidence Score: Not applicable
Threat Persistence: NONE
- Threat Observation Count: 0
- Persistently Malicious: No
- Campaign Likelihood: Not detected
---
## Network Context
Subnet Analysis (5.196.136.0/24)
- Abuse Density: 0% (Clean classification)
- Active Siblings: 0
- Threat Siblings: 0
- Neighboring IP: 5.196.136.129 (Risk Score: 25)
Network Stability
- Route Stability: False
- BGP Prefix: 5.196.0.0/16
- Route Changes (30d): 0
---
## Observation History (19 Signals)
Recent signals (2026-06-21) indicate:
- DNS Listings: 8 total listings (1 active, high severity classification noted)
- Operator Score: 0.2609 (Label: Basic)
- ASN Resolution: AS16276 OVH SAS confirmed
- Geolocation Signals: Multiple sources confirming France origin
- DNSSEC Status: Valid
No escalation trends observed in temporal data.
---
## Technical Services Assessment
Active Services: NONE
- Open Ports: 0 detected
- TLS Certificates: None
- HTTP Banner: None
- Connection State: Firewalled / No Services
DNS Configuration
- Forward Resolution: Confirmed (1 hostname)
- Reverse Lookup: Confirmed (ip132.ip-5-196-136.eu)
- SPF Record: Not configured
- DMARC Record: Present
---
## Recommended Actions
Current Risk Level: LOW
No immediate firewall rules or blocking actions recommended. Standard network monitoring protocols apply.
Monitoring Recommendations:
- Continue standard traffic observation
- Monitor for service activation on previously silent ports
- Review DNS association with ip132.ip-5-196-136.eu for any suspicious domain activity
---
## Intelligence Conclusions
IP 5.196.136.132 represents standard OVH cloud infrastructure with no evidence of malicious activity. The low risk score (25/100) and clean neighborhood profile support classification as benign cloud hosting. No blocking or restrictive firewall rules are warranted at this time.
Classification: CLEAN / LOW RISK
Priority: STANDARD MONITORING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | OVH SAS |
| ASN | AS16276 |
| Network Name | OVH_496625479 |
| CIDR Block | 5.196.136.128/28 |
| RIR | RIPE |
| Country | FR |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | ip132.ip-5-196-136.eu |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | ip132.ip-5-196-136.eu |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Not configured |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 19% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 13% | 1 | 1 |
| ownership | 27% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 15% | 2 | 2 |
| Overall | 17% | 9 | 11 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-29 12:05:20 UTC |
| Last Seen | 2026-06-29 06:31:13 UTC |
| Profile Built | 2026-06-29 06:35:31 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 21 |
Full dossier details are available via our API.