# IP INTELLIGENCE BRIEFING: 92.222.230.165/32
Classification: Moderate Risk (Score: 50) | Timestamp: 2026-06-28 | Status: Active
## EXECUTIVE SUMMARY
IP address 92.222.230.165 is a cloud hosting VPS instance operated by OVH SAS in Paris, France. The IP presents moderate risk (score 50/100) with limited threat indicators. No active malicious campaigns, open services, or known attacker signatures detected. Recommended for monitoring rather than immediate blocking.
## OWNERSHIP AND INFRASTRUCTURE
- ASN: 16276 (OVH SAS)
- Location: Paris, Île-de-France, France (FR)
- Infrastructure Type: CloudCompute (VPS)
- CIDR Block: 92.222.0.0/16
- DNS Resolution: vps-baf9b08d.vps.ovh.net (Forward confirmed)
- Email Authentication: SPF and DMARC records present
## THREAT INDICATORS
- Blacklist Status: Listed on 1 of 8 DNSBLs
- Threat Reputation: No known attacker campaigns
- Tor Exit Node: No
- Proxy/VPN: No
- C2 Activity: None detected
- Known Bad IPs: False
## NETWORK CLASSIFICATION
- Role: Hosting Provider (VPS)
- Services: No open ports detected; service classified as "Firewalled / No Services"
- Connection Type: Cloud infrastructure
- Mobile/Residential: False
## GEOLOCATION VALIDATION
- Coordinates: 46.23°N, 2.21°E (Paris region)
- Accuracy Radius: 500km
- Consensus: True (multi-source)
## NEIGHBORHOOD ANALYSIS (92.222.230.0/24)
- Abuse Density: 0 (clean)
- Classification: Mostly clean
- Active Siblings: 1
- Threat Siblings: 1
- Inherited Risk: 2/100
## OBSERVATION HISTORY
- Total Observations: 25 signals
- Last Observed: 2026-06-28
- Threat Persistence: 0 days
- Ownership Changes: 0
- Status: Not persistently malicious
## RELATIONSHIP GRAPH
- DNS Associations: vps-baf9b08d.vps.ovh.net (multiple entries)
- Network Associations: VPS-EU-WEST-RBX-VPS-1
- Total Relationships: 49
## RECOMMENDED ACTIONS
Based on risk score 50 and moderate classification:
1. Monitor rather than block (risk score below 60 threshold)
2. Log all traffic for forensic analysis
3. Block only if additional indicators present (no current evidence)
Firewall Rules (if blocking required):
```bash
iptables -A INPUT -s 92.222.230.165 -j DROP
nft add rule inet filter input ip saddr 92.222.230.165 drop
```
## SOC ANALYST NOTES
This IP represents a legitimate OVH VPS instance with no active malicious behavior. The moderate risk score stems from DNSBL listing rather than confirmed threats. Standard logging and monitoring recommended; immediate blocking not warranted without additional corroborating indicators.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
| Enumeration | Path/resource enumeration | 1 |
๐ข Ownership & Registration
| Organization | OVH SAS |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vps-baf9b08d.vps.ovh.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | vps-09bc555e.vps.ovh.net |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 17% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 24% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-20 05:45:37 UTC |
| Last Seen | 2026-06-28 11:33:13 UTC |
| Profile Built | 2026-06-29 05:35:58 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 28 |
Full dossier details are available via our API.