IP INTELLIGENCE BRIEFING: 94.23.69.29/32
Classification: Cloud Infrastructure Host (Moderate Risk)
Report Date: Current
Primary Provider: OVH Srl (AS16276)
---
EXECUTIVE SUMMARY
IP 94.23.69.29 is a cloud computing host operated by OVH Srl with a moderate risk profile (55/100). The IP is associated with Microsoft-IIS/7.5 server software and is listed on 3 of 8 DNSBLs. While the immediate neighborhood shows minimal abuse density, the control plane indicates routing instability with BGP prefix 94.23.0.0/16 not route-stable.
---
TECHNICAL PROFILE
Network Classification:
- Provider: OVH Srl (OVH)
- ASN: AS16276
- Infrastructure Type: Cloud Compute
- Hosting: Yes
- Location: Italy (IT)
- CIDR Block: 94.23.0.0/16
Service Exposure:
- Port 80/tcp: HTTP (Open)
- Port 3389/tcp: RDP (Open) โ *Notable for cloud infrastructure*
- Server Fingerprint: Microsoft-IIS/7.5
DNS Configuration:
- PTR Record: ip29.ip-94-23-69.eu
- Forward Resolution: Confirmed (1 hostname)
- DNSBL Listings: 3/8 lists
- SPF: Not configured
- DMARC: Configured
---
THREAT INDICATORS
Current Signals:
- Risk Score: 55/100 (Moderate)
- DNSBL Listings: 3 active listings
- Control Plane: Route instability detected (isRouteStable: false)
- Operator Score: 0.2609 (Basic classification)
- ISP Classification: Proxy/VPN signals observed in historical data
Threat Assessment:
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Campaign Association: None detected
- Historical Threat Persistence: 0 days (not persistently malicious)
---
OBSERVATION HISTORY
Recent signal observations (2026-06-20) indicate:
- 24 total observations recorded
- Operator score signals with max severity "high"
- Multiple proxy/VPN type classifications observed
- HTTP server responses with 404 status codes
- Average Time-to-First-Byte: 200ms
---
NEIGHBORHOOD ANALYSIS (94.23.69.0/24)
- Abuse Density: 0 (Low)
- Classification: Mostly Clean
- Active Siblings: 1
- Threat Siblings: 1
- Overall Risk Inherited: 2/100
---
RECOMMENDED ACTIONS
Security Recommendations:
1. Increase logging verbosity for traffic from this IP
2. Review recent activity from source 94.23.69.29
3. Consider blocking at perimeter given moderate risk profile
Firewall Rules:
- iptables: `iptables -A INPUT -s 94.23.69.29 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 94.23.69.29 drop`
- nginx: `deny 94.23.69.29;`
- pfSense: `94.23.69.29/32`
WAF Rules:
- Cloudflare WAF: Block with expression `ip.src eq 94.23.69.29`
- AWS WAF: Add CIDR block `94.23.69.29/32` to protected resources
---
INTELLIGENCE NOTES
The IP hosts RDP service on port 3389, which may indicate either legitimate cloud infrastructure or potential lateral movement vector. The presence of 3 DNSBL listings warrants investigation if traffic from this IP is observed. Route instability in the BGP prefix may indicate infrastructure changes or potential abuse infrastructure migration.
Analyst Action: Monitor for additional threat indicators and correlate with internal traffic patterns.
---
*Report generated from IPDebrief intelligence platform data.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | OVH Srl |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | ip29.ip-94-23-69.eu |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | ip29.ip-94-23-69.eu |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Not configured |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Multi-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 3389 | rdp | tcp | โ |
| Closed Ports | 22, 25, 443, 8080, 8443 (2 open / 7 scanned) | ||
| Server | Microsoft-IIS/7.5 |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 26% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-15 08:45:07 UTC |
| Last Seen | 2026-06-28 02:16:31 UTC |
| Profile Built | 2026-06-28 20:21:50 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 27 |
Full dossier details are available via our API.