# IP Intelligence Briefing: 142.44.220.124/32
## Executive Summary
IP 142.44.220.124 is a cloud hosting infrastructure address operated by OVH (ASN 16276) on behalf of Dmytro, Ahrefs Pte Ltd. The IP carries a moderate risk score of 40 and operates within a high-abuse subnet (142.44.220.0/24). While no active threat indicators were detected, the neighborhood abuse density of 0.6523 warrants defensive posture consideration.
## Ownership and Infrastructure
- Organization: Dmytro, Ahrefs Pte Ltd
- Network: OVH-CUST-281059685 (142.44.220.0/24)
- ASN: 16276
- Infrastructure Type: CloudCompute (hosting provider)
- Registration: ARIN RIR
## Geolocation Anomalies
Significant geolocation inconsistencies detected:
- Reported Location: Canada (CA), Quebec, Singapore
- Coordinates: Invalid (null values)
- Validation Failure: 5,597.9 km distance violation with 31ms RTT (minimum possible 112ms)
- Consensus: Geo-plausible flag set to false across multiple probes
## Threat Assessment
Current Risk Score: 40 (Moderate Risk)
Active Threat Indicators: None detected
- Not a known attacker
- Not a spam source
- Not a Tor exit node
- No active threat campaigns
- Zero blacklist entries (0/8 DNSBL lists)
Control Plane:
- DNSSEC: Valid
- CAA Records: Present
- BGP Prefix: 142.44.128.0/17
- Route Stability: Not stable
- IRR Consistency: Inconsistent
## Neighborhood Risk Analysis
Subnet 142.44.220.0/24 demonstrates elevated abuse characteristics:
- Abuse Density: 0.6523 (High Abuse Classification)
- Active Siblings: 175 of 256 total
- Threat Siblings: 167
- Inherited Risk: 26
Risk distribution across sampled neighbors: 60% medium risk, 40% low risk, 0% high risk.
## DNS and Service Profile
- PTR Hostname: proxy-ca006-san124.ahrefs.net
- Domain: ahrefs.net
- Services: No open ports detected (Firewalled/No Services)
- HTTP: No services responding
- Email Authentication: SPF/DMARC not configured
## Historical Signals (21 Observations)
Recent telemetry (June 2026) confirms:
- Infrastructure consistently classified as CloudCompute
- Abuse density signals persisting at 0.6523
- No ownership changes recorded
- Threat persistence days: 0 (not persistently malicious)
## Security Recommendations
Recommended Actions: Block based on moderate risk score and high-abuse subnet context
Firewall Rules:
- iptables: `iptables -A INPUT -s 142.44.220.124 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 142.44.220.124 drop`
- nginx: `deny 142.44.220.124;`
- pfSense: `142.44.220.124/32` (block rule)
- Cloudflare WAF: Block with expression `ip.src eq 142.44.220.124`
- AWS WAF: Add address `142.44.220.124/32` with description "IPDebrief risk 40"
## SOC Analyst Notes
This IP represents legitimate cloud hosting infrastructure but operates in an elevated-risk subnet. The geolocation anomalies suggest potential misconfiguration or data quality issues. While no active malicious indicators were observed, the high neighborhood abuse density (167 threat siblings) suggests the subnet may host compromised infrastructure. Recommend monitoring for changes in DNS records or service emergence, and consider blocking at the perimeter firewall level.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059685 |
| CIDR Block | 142.44.220.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca006-san124.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca006-san124.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 25% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-12 21:53:57 UTC |
| Last Seen | 2026-06-27 21:58:16 UTC |
| Profile Built | 2026-06-28 16:03:55 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 25 |
Full dossier details are available via our API.