## IP Intelligence Briefing: 5.196.190.161
Date: 2026-06-20
Status: Active Threat Indicator
Risk Classification: Moderate Risk (55/100)
Executive Summary
IP address 5.196.190.161 is a French cloud infrastructure endpoint operated by OVH (ASN 16276) with elevated risk indicators. The IP is associated with the domain nobushige.ninja and has been observed on 3 of 8 DNSBL feeds. While the subnet (5.196.190.0/24) shows low abuse density (1/24), the specific endpoint warrants defensive monitoring.
Technical Profile
| Attribute | Value |
|---|---|
| **Organization** | UAB OVH |
| **ASN** | 16276 |
| **Country** | France (FR) |
| **Infrastructure** | Cloud Compute, Hosting Provider |
| **Network Role** | Firewalled / No Services |
| **DNS Resolution** | info6.b.nobushige.ninja |
| **Blacklist Status** | 3/8 DNSBL lists |
| **Tor/Exit Node** | No |
| **Known Attacker** | No |
| **Spam Source** | No |
Threat Indicators
- DNSBL Listings: 3 confirmed blacklist entries across 8 total lists
- Operator Score: 0.1304 (Minimal risk classification)
- Route Stability: False (dynamic routing patterns detected)
- Threat Persistence: 0 days (no persistent malicious activity observed)
- Campaign Correlation: 0 matches in known threat campaigns
Network Neighborhood Analysis
- Subnet: 5.196.190.0/24
- Abuse Density: 1 (low density classification)
- Threat Siblings: 1 identified within subnet
- Active Siblings: 0
- Classification: Mostly clean
Historical Observations (18 signals)
Recent monitoring (2026-06-20) confirms consistent cloud hosting classification. Historical data from 2026-06-15 indicates the subnet was classified as "mostly_clean" with 1 threat sibling. No significant risk escalation detected over observation period.
Recommended Actions
Immediate:
- Implement firewall blocking per risk score (55/100)
- Increase logging verbosity for this IP
- Review recent activity logs for this address
Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 5.196.190.161 -j DROP
# nftables
nft add rule inet filter input ip saddr 5.196.190.161 drop
# Cloudflare WAF
Expression: ip.src eq 5.196.190.161 (Block)
# AWS WAF
Addresses: 5.196.190.161/32 (Block)
```
Intelligence Assessment
This IP represents a moderate-risk hosting infrastructure endpoint with no confirmed malicious activity but elevated threat indicators. The association with nobushige.ninja and presence on multiple DNSBL feeds suggests potential misuse or compromise. While the subnet shows low abuse density, the specific endpoint warrants blocking at perimeter defenses. Monitor for related IPs in the 5.196.190.0/24 range.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | UAB OVH |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | info6.b.nobushige.ninja |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | info6.b.nobushige.ninja |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | 0/2 domains |
| DMARC | 1/2 domains |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
| Domains Checked | 2 domains |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 22% | 9 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-24 18:41:26 UTC |
| Last Seen | 2026-06-29 00:38:55 UTC |
| Profile Built | 2026-06-29 06:42:37 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 21 |
Full dossier details are available via our API.