IPDebrief

54.37.252.36

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IPDEBRIEF INTELLIGENCE BRIEFING

## Target: 54.37.252.36/32

EXECUTIVE SUMMARY

The IP address 54.37.252.36 is a cloud compute infrastructure endpoint owned by OVH SAS, located in France. The asset carries a moderate risk score (50/100) with no active threat indicators. The IP hosts an SSH service on port 22 and resolves to hostname ns3114111.ip-54-37-252.eu. While the individual IP shows no malicious activity, its /24 subnet exhibits elevated abuse density (0.5714), indicating potential collateral risk from neighboring addresses.

---

NETWORK OWNERSHIP & GEOGRAPHY

THREAT ASSESSMENT

MetricValueAssessment
Risk Score50Moderate
Provider Score0Neutral
Authority Score0Neutral
Known AttackerNoClear
Tor Exit NodeNoClear
Spam SourceNoClear
Blacklist Count0Clean

Threat Indicators: None detected. No known campaigns, threat feeds, or abuse confidence scores associated with this IP.

NETWORK SERVICES & FINGERPRINT

NEIGHBORHOOD ANALYSIS (54.37.252.0/24)

The /24 subnet shows elevated abuse characteristics requiring contextual monitoring:

Neighbor Risk Distribution:

Key neighboring addresses requiring attention: 54.37.252.231 (risk 50), 54.37.252.46/59/118/119/130/152/153/229 (risk 40).

OBSERVATION HISTORY

RELATIONSHIP GRAPH

The IP maintains 50 recorded relationships, primarily:

RECOMMENDED ACTIONS

Based on risk profile (50), the following defensive measures are recommended:

PlatformAction
iptables`iptables -A INPUT -s 54.37.252.36 -j DROP`
nftables`nft add rule inet filter input ip saddr 54.37.252.36 drop`
nginx`deny 54.37.252.36;`
pfSense`54.37.252.36/32`
Cloudflare WAFBlock with expression: `ip.src eq 54.37.252.36`
AWS WAFAdd 54.37.252.36/32 to block list

Note: These recommendations are probabilistic. Correlate with additional signals before enforcement.

SOC ANALYST NOTES

1. Low Immediate Threat: The IP itself shows no active malicious behavior. Blocking may impact legitimate OVH cloud services.

2. Subnet Context: The 54.37.252.0/24 subnet shows high abuse density. Consider evaluating 54.37.252.231 (risk 50) for additional threat context.

3. Infrastructure Type: As a cloud hosting endpoint, this IP may be legitimately used for web hosting, development, or legitimate services.

4. SSH Exposure: Port 22 is open; ensure SSH traffic is not being abused for lateral movement attempts.

5. DNSBL Listings: 2 of 8 total lists flag this IP; investigate specific list contents if receiving complaints.

---

*Report generated: 2026-06-26 | Source: IPDebrief Intelligence Platform*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ซ๐Ÿ‡ท France
Regionโ€”
Cityโ€”
TimezoneEurope/Paris
Latitude48.86
Longitude2.34

๐Ÿข Ownership & Registration

OrganizationOVH SAS
ASNAS16276
Network Nameโ€”
CIDR Blockโ€”
RIRARIN
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRns3114111.ip-54-37-252.eu
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnamesns3114111.ip-54-37-252.eu

๐Ÿ” DNS Hygiene

Hygiene Score60% (Good)
SPFPresent
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeSingle-Service Host
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
22sshtcp
Closed Ports25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”
SSH VersionSSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
45%
25
routing
13%
11
services
12%
22
ownership
24%
23
reputation
31%
13
geolocation
23%
22
Overall25%1016
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-10 16:14:41 UTC
Last Seen2026-06-27 18:05:51 UTC
Profile Built2026-06-28 12:10:21 UTC
Data FreshnessLive
Signal Types21
Total Observations28
๐Ÿ” 21 signal types ยท 28 observations collected
This report is generated from 21+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.