## IP Intelligence Briefing: 54.36.132.213
Classification: Moderate Risk (Score: 50/100)
Date: Current Analysis
Jurisdiction: Switzerland (CH)
Provider: OVH CH (ASN: 16276)
Executive Summary
IP 54.36.132.213 is a cloud hosting infrastructure address belonging to OVH CH (OVH-DEDICATED-FO). The IP presents a moderate risk profile with no active threat indicators. The address is classified as clean within its /24 subnet with zero abuse density. No malicious activity patterns detected in 21 historical observations.
Technical Profile
Network Classification:
- Infrastructure Type: Cloud Compute / Hosting
- Connection Type: IPv4 Dedicated Host
- DNS Reverse: ip213.ip-54-36-132.eu
- Forward Resolution: ip213.ip-54-36-132.eu (confirmed)
Risk Indicators:
- Risk Score: 50 (Moderate)
- Abuse Confidence: Not assigned
- Blacklist Status: 2 DNSBL listings out of 8 total lists
- Threat Indicators: None detected
- Known Campaigns: None correlated
Network Neighborhood (54.36.132.0/24):
- Subnet Classification: Clean
- Abuse Density: 0%
- Threat-Sibling Count: 0
- Risk Distribution: No high/medium risk neighbors observed
Operational Observations
Services: No open ports detected. Connection type marked as "Firewalled / No Services."
Temporal Analysis:
- Ownership Stability: No changes recorded
- Threat Persistence: Not persistently malicious
- Observation Count: 21 historical signals
- Recent Activity: Signals observed through August 2026
Control Plane:
- BGP Prefix: 54.36.0.0/16
- Origin ASN: 16276
- Route Stability: False (route changes observed in last 30 days)
- DNSSEC: Validated
Threat Assessment
No active threat indicators detected. The IP address shows characteristics typical of legitimate OVH cloud hosting infrastructure. The moderate risk score (50) reflects the IP's classification in a shared cloud hosting environment, not evidence of malicious activity. No known attack campaigns, spam sources, or attacker behavior patterns observed.
Recommended Actions
Defensive Measures:
- No specific blocking recommended based on current risk profile
- Standard logging and monitoring advised for cloud hosting traffic
- Consider blocking only if specific threat indicators emerge
Implementation Rules:
- iptables: `iptables -A INPUT -s 54.36.132.213 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 54.36.132.213 drop`
- Cloudflare WAF: Block with expression `ip.src eq 54.36.132.213`
Conclusion
IP 54.36.132.213 represents standard OVH cloud hosting infrastructure with no evidence of malicious activity. The moderate risk classification is attributable to the shared hosting environment rather than confirmed threats. SOC teams may monitor traffic patterns but no immediate blocking action is warranted based on available intelligence.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | OVH CH |
| ASN | AS16276 |
| Network Name | OVH-DEDICATED-FO |
| CIDR Block | 54.36.132.208/28 |
| RIR | ARIN |
| Country | CH |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | ip213.ip-54-36-132.eu |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | ip213.ip-54-36-132.eu |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 24% | 2 | 2 |
| ownership | 35% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 27% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-08-03 23:39:16 UTC |
| Last Seen | 2026-08-13 06:45:10 UTC |
| Profile Built | 2026-08-13 06:05:48 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 26 |
Full dossier details are available via our API.