## INTELLIGENCE BRIEFING: 142.44.220.111/32
Classification: Moderate Risk β Cloud Infrastructure with Elevated Neighborhood Threat Density
IP Address: 142.44.220.111
ASN: 16276 (OVH SAS)
Organization: Dmytro, Ahrefs Pte Ltd
Network Block: 142.44.220.0/24
Ownership and Infrastructure
The IP address resolves to OVH cloud infrastructure under customer identifier OVH-CUST-281059685. The PTR record indicates hostname proxy-ca006-san111.ahrefs.net, associated with the ahrefs.net domain. No active services are detected on this address.
Risk Assessment
The IP carries a risk score of 50, classified as Moderate Risk. No active threat indicators were identifiedβno Tor exit node activity, no known attacker attribution, and no spam source classification. However, the address is listed on two DNSBLs out of eight total lists monitored.
Geolocation Validation
Geolocation data shows the IP claimed location as Canada (Quebec), but RTT-based validation flagged a significant discrepancy. The observed minimum RTT of 27ms contradicts the 112ms minimum possible for the claimed 5,598km distance, indicating geolocation data may be unreliable.
Neighborhood Context
The /24 subnet 142.44.220.0/24 exhibits elevated threat density with an abuse classification of high_abuse. Of 256 total siblings, 175 are currently active and 166 are classified as threats. The subnet's inherited risk score is 25, with an abuse density of 0.6484.
Historical Observations
Analysis of 21 signal observations reveals persistent listing activity. Recent data from June 22, 2026, shows the IP listed on eight blacklist sources with one high-severity entry. Operator routing score remains minimal at 0.2174.
Recommended Actions
No specific firewall actions are currently recommended. The address should be monitored given its neighborhood context, but immediate blocking is not warranted absent additional threat indicators.
Intel Analyst Notes: This IP represents cloud-hosted infrastructure in a high-abuse subnet. The ahrefs.net association suggests legitimate SEO/business operations, but the listing presence and neighborhood density warrant continued observation.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059685 |
| CIDR Block | 142.44.220.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca006-san111.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca006-san111.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 22% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:03:42 UTC |
| Last Seen | 2026-06-26 22:39:28 UTC |
| Profile Built | 2026-06-27 18:52:14 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 29 |
Full dossier details are available via our API.