# IP Intelligence Briefing: 79.137.89.206/32
## Executive Summary
IP 79.137.89.206 is classified as a Moderate Risk infrastructure address hosted by OVH SAS. The IP shows no active threat indicators but is listed on 2 of 8 DNSBLs, suggesting potential reputation issues. No immediate malicious activity was observed.
## Infrastructure Profile
Ownership & Network:
- Organization: OVH SAS (ASN: 16276)
- Network Name: SD-onenetwork
- CIDR Block: 79.137.89.0/24
- Registry: RIPE NCC
- Infrastructure Type: Cloud Computing / Hosting Provider
- Geolocation: France (FR)
DNS Resolution:
- PTR Hostname: ns3239205.ip-79-137-89.eu
- Forward Resolution: Confirmed
- Hosted Domains: 0 (DNS-only address)
Network Classification:
- Status: Cloud infrastructure with firewall protection
- Open Ports: None detected
- Services: Firewalled / No Services exposed
- DNSSEC Valid: Yes
## Risk Assessment
Current Risk Score: 50/100 (Moderate)
Threat Indicators:
- Abuse Confidence Score: Not reported
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Blacklist Count: 0 (current blacklist count)
- DNSBL Listed: 2 of 8 total lists
Control Plane Anomalies:
- Route Stability: Unstable
- RPKI State: Not evaluated
- Route Changes (30d): 0
- Operator Score: 0.2609 (Basic)
## Observation History
Signal Count: 16 historical observations
Key Timeline Events:
- 2026-08-13 15:45:15 โ Ownership confirmed: OVH SAS, RIR RIPE, CIDR 79.137.89.0/24
- 2026-08-13 15:46:48 โ Traceroute observed 30 hops (17 timed out), geolocation inferred US (likely false positive)
- 2026-08-13 15:47:51 โ Ownership stability confirmed (0 changes)
Temporal Analysis:
- Ownership Changes: 0
- Threat Persistence Days: 0
- Threat Observation Count: 0
- Persistently Malicious: No
## Relationship Mapping
Connected Entities:
- DNS Associations: ns3239205.ip-79-137-89.eu (multiple entries)
- Network Associations: SD-onenetwork (OVH)
- Total Relationships: 8
No external organizational links or certificate associations detected.
## Neighborhood Analysis
/24 Subnet: 79.137.89.0/24
- Neighbor Count: 0 (no active sibling IPs detected)
- Abuse Density: 0
- Threat Siblings: 0
- Classification: Low risk subnet profile
## Recommended Security Actions
Blocking Rules Available:
- iptables: `iptables -A INPUT -s 79.137.89.206 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 79.137.89.206 drop`
- nginx: `deny 79.137.89.206;`
- pfSense: Block rule for 79.137.89.206/32
- Cloudflare WAF: Block rule with description "IPDebrief risk score 50"
- AWS WAF: Block IP 79.137.89.206/32
Analysis Note: Actions are probabilistic and should be combined with other threat signals before implementation.
## Intelligence Assessment
This IP represents standard OVH cloud infrastructure with no active malicious indicators. The moderate risk score (50) is primarily driven by DNSBL listings and route instability rather than confirmed malicious activity. The subnet shows clean neighborhood data with no adjacent abuse patterns.
Recommended Action: Monitor or block based on organizational risk tolerance. No immediate threat detected.
Classification: Moderate Risk โ Cloud Infrastructure
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | OVH SAS |
| ASN | AS16276 |
| Network Name | SD-onenetwork |
| CIDR Block | 79.137.89.0/24 |
| RIR | RIPE |
| Country | FR |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | ns3239205.ip-79-137-89.eu |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | ns3239205.ip-79-137-89.eu |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | 6/6 domains |
| DMARC | 0/6 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
| Domains Checked | 6 domains |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | Apache/2.4.62 (Debian) |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | file.fosfor.tech |
| Valid From | 2026-08-16T02:32:06+00:00 |
| Valid Until | 2026-11-14T02:32:05+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
| Serial Number | 056E3FF67FDD157724EBBC85305CD407D1D3 |
| Thumbprint | DDDD24014D9ED1984270A853BBB64E927C2A96F3 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 25% | 2 | 4 |
| ownership | 17% | 2 | 3 |
| reputation | 13% | 1 | 1 |
| geolocation | 15% | 2 | 2 |
| Overall | 18% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-08-11 11:50:23 UTC |
| Last Seen | 2026-09-14 10:02:19 UTC |
| Profile Built | 2026-09-14 10:12:04 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 36 |
Full dossier details are available via our API.