IP Intelligence Briefing: 54.38.179.233
Date: June 16, 2026
---
**1. Risk Profile**
- Risk Score: 80 (High Risk)
- Provider: OVH SAS (France)
- Network Role: Cloud Compute Hosting (nginx/1.18.0)
- Threat Indicators: No direct malware, phishing, or exploitation activity detected.
---
**2. Geolocation & Ownership**
- Country: France (FR)
- ASN: 16276 (OVH SAS)
- Subnet: 54.38.179.233/24
- Hosting: Legitimate cloud server for "moritstech.com" (HTTP/HTTPS services).
---
**3. Network & Service Analysis**
- Services:
- Open ports: 80 (HTTP), 443 (HTTPS), 22 (SSH).
- TLS Certificate: Valid (Letβs Encrypt), SANs include "moritstech.com".
- SSH Banner: "SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15".
- DNS:
- PTR hostname: "mail.moritstech.com".
- No SPF/DKIM records for email authentication.
---
**4. Observation History**
- Recent Activity (Last 30 Days):
- Stable network (no route changes).
- No persistent malicious behavior detected.
- Low threat observation count (1).
---
**5. Relationships & Neighborhood**
- Related Entities:
- Linked to network "SD-1G-GRA-G208" (OVH infrastructure).
- No direct ties to known malicious campaigns or C2 servers.
- Subnet Analysis:
- 54.38.179.233/24: No neighboring IPs identified (abuse density: 0).
---
**6. Recommendations**
1. Monitor DNS Configuration: Ensure "moritstech.com" implements SPF/DKIM to prevent spoofing.
2. Secure SSH Access: Restrict SSH access to trusted IPs and use strong authentication.
3. Watch for Subnet Changes: Track 54.38.179.233/24 for unexpected network activity.
4. Verify Certificate Validity: Confirm Letβs Encrypt certificate is up-to-date and properly configured.
---
Conclusion:
The IP is a legitimate OVH-hosted server with no direct malicious activity. However, its lack of DNS security measures and high risk score warrant closer monitoring. No immediate action is required, but ensure configurations align with organizational security policies.
Source: IPDebrief Threat Intelligence Platform
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | OVH SAS |
| ASN | AS16276 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | mail.moritstech.com |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | mail.moritstech.com |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | nginx/1.18.0 (Ubuntu) |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15 |
π TLS Certificate
| SANs | moritstech.comwww.moritstech.com |
| Valid From | 2026-05-18T01:05:56+00:00 |
| Valid Until | 2026-08-16T01:05:55+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 89 days |
| Serial Number | 06035F54D1D26AC885182B1ED61441BAE46C |
| Thumbprint | A68CFCE8EA20D4D1A04E3F3AA50CA85C5A230A71 |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 26% | 2 | 3 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 25% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:28 UTC |
| Last Seen | 2026-06-27 07:55:00 UTC |
| Profile Built | 2026-06-28 02:00:58 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 29 |
Full dossier details are available via our API.