IPDebrief

5.196.190.161

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

## IP Intelligence Briefing: 5.196.190.161

Date: 2026-06-20

Status: Active Threat Indicator

Risk Classification: Moderate Risk (55/100)

Executive Summary

IP address 5.196.190.161 is a French cloud infrastructure endpoint operated by OVH (ASN 16276) with elevated risk indicators. The IP is associated with the domain nobushige.ninja and has been observed on 3 of 8 DNSBL feeds. While the subnet (5.196.190.0/24) shows low abuse density (1/24), the specific endpoint warrants defensive monitoring.

Technical Profile

AttributeValue
**Organization**UAB OVH
**ASN**16276
**Country**France (FR)
**Infrastructure**Cloud Compute, Hosting Provider
**Network Role**Firewalled / No Services
**DNS Resolution**info6.b.nobushige.ninja
**Blacklist Status**3/8 DNSBL lists
**Tor/Exit Node**No
**Known Attacker**No
**Spam Source**No

Threat Indicators

Network Neighborhood Analysis

Historical Observations (18 signals)

Recent monitoring (2026-06-20) confirms consistent cloud hosting classification. Historical data from 2026-06-15 indicates the subnet was classified as "mostly_clean" with 1 threat sibling. No significant risk escalation detected over observation period.

Recommended Actions

Immediate:

Firewall Rules:

```bash

# iptables

iptables -A INPUT -s 5.196.190.161 -j DROP

# nftables

nft add rule inet filter input ip saddr 5.196.190.161 drop

# Cloudflare WAF

Expression: ip.src eq 5.196.190.161 (Block)

# AWS WAF

Addresses: 5.196.190.161/32 (Block)

```

Intelligence Assessment

This IP represents a moderate-risk hosting infrastructure endpoint with no confirmed malicious activity but elevated threat indicators. The association with nobushige.ninja and presence on multiple DNSBL feeds suggests potential misuse or compromise. While the subnet shows low abuse density, the specific endpoint warrants blocking at perimeter defenses. Monitor for related IPs in the 5.196.190.0/24 range.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ซ๐Ÿ‡ท France
Regionโ€”
Cityโ€”
TimezoneEurope/Paris
Latitude48.86
Longitude2.34

๐Ÿข Ownership & Registration

OrganizationUAB OVH
ASNAS16276
Network Nameโ€”
CIDR Blockโ€”
RIRRIPE
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRinfo6.b.nobushige.ninja
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesinfo6.b.nobushige.ninja

๐Ÿ” DNS Hygiene

Hygiene Score40% (Fair)
SPF0/2 domains
DMARC1/2 domains
FCrDNSNot verified
DNSSECValid
CAANot configured
Domains Checked2 domains

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
27%
23
routing
13%
11
services
8%
11
ownership
24%
23
reputation
26%
13
geolocation
33%
23
Overall22%914
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-24 18:41:26 UTC
Last Seen2026-06-29 00:38:55 UTC
Profile Built2026-06-29 06:42:37 UTC
Data FreshnessLive
Signal Types19
Total Observations21
๐Ÿ” 19 signal types ยท 21 observations collected
This report is generated from 19+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.