# IP Intelligence Briefing: 72.251.5.145/32
Classification: Cloud Compute Infrastructure
Date: August 2026
Risk Level: Low Risk (Score: 25/100)
---
## Executive Summary
IP 72.251.5.145 is a low-risk cloud compute endpoint hosted by OVH. The address shows minimal threat indicators and no active malicious activity. However, geolocation validation issues and moderate subnet abuse density warrant continued monitoring.
---
## Technical Profile
Ownership & Registration:
- ASN: 16276 (OVH)
- Organization: Private Customer (OVH-CUST-481309263)
- CIDR Block: 72.251.5.144/28
- RIR: ARIN
Network Classification:
- Infrastructure Type: Cloud Compute
- Hosting: Yes
- CDN/Proxy/VPN: No
- Mobile/Residential: No
DNS Resolution:
- PTR Hostname: ip145.ip-72-251-5.net
- Forward Resolution: Confirmed
- Hosted Domains: None
Services Status:
- Open Ports: None detected
- HTTP/TLS: No services running
- Firewall/No Services: Active
---
## Threat Assessment
Threat Indicators:
- Abuse Confidence Score: Not applicable
- Blacklist Count: 0
- Is Tor Exit: No
- Is Known Attacker: No
- Is Spam Source: No
- Pulsedive Risk: Not applicable
Control Plane:
- Route Stability: Unstable (isRouteStable: false)
- DNSBL Listed: 1 of 8 lists
- Operator Score: 0.1304 (Minimal)
---
## Geolocation Analysis
Claimed Location: Canada (CA)
Validation Status: Failed
Discrepancies Detected:
- RTT Analysis: 33ms observed vs 121.6ms minimum required for 6,082km distance
- GeoPlausible: False
- Multiple geolocation sources report inconsistent locations
- One historical observation placed the IP in Colombia with 95% confidence
Assessment: Geolocation data is unreliable. IP should not be trusted for location-based decisioning.
---
## Historical Observations
Total Observations: 16
Threat Persistence Days: 0
Persistently Malicious: No
Key Historical Signals:
- Ownership changes: 0
- Threat observation count: 0
- Subnet classification: "mostly_clean"
- No evidence of persistent malicious behavior
---
## Network Neighborhood Analysis
Subnet: 72.251.5.145/24
Abuse Density: 0.6667 (66.67%)
Classification: Mostly Clean
Identified Neighbors:
| IP Address | Risk Score | Authority Score | Status |
|---|---|---|---|
| 72.251.5.146 | 25 | 60 | Low Risk |
| 72.251.5.158 | 25 | 60 | Low Risk |
Risk Distribution: High: 0, Medium: 0, Low: 2
---
## Relationship Graph
Associated Entities:
- DNS: ip145.ip-72-251-5.net (multiple associations)
- Network: OVH-CUST-481309263 (multiple same-network relationships)
---
## Recommended Actions
Firewall Rules: No specific blocking required
Monitoring: Continue standard monitoring
Threat Hunting: No immediate threat indicators
Actionable Guidance:
- IP poses low risk; no immediate blocking recommended
- Monitor for changes in service status or threat indicators
- Subnet abuse density (66.67%) suggests elevated background activity in neighborhood
- Consider enhanced logging if this IP initiates connections from protected segments
---
Briefing End
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Private Customer |
| ASN | AS16276 |
| Network Name | OVH-CUST-481309263 |
| CIDR Block | 72.251.5.144/28 |
| RIR | ARIN |
| Country | Colombia |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | ip145.ip-72-251-5.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | ip145.ip-72-251-5.net |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | nginx/1.21.5 |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6 |
๐ TLS Certificate
| SANs | None |
| Valid From | 2026-04-09T03:36:46+00:00 |
| Valid Until | 2036-04-06T03:36:46+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 3650 days |
| Serial Number | 407458B939BD0BBE05EB7ECC96E160EEB8ADCD24 |
| Thumbprint | 0EAEB64E94D40774634373F6AEF59058606778DE |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 35% | 2 | 4 |
| ownership | 19% | 2 | 2 |
| reputation | 13% | 1 | 2 |
| geolocation | 33% | 2 | 4 |
| Overall | 24% | 10 | 16 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-08-07 13:25:38 UTC |
| Last Seen | 2026-08-30 17:58:54 UTC |
| Profile Built | 2026-08-30 18:06:04 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 28 |
Full dossier details are available via our API.