IP Intelligence Briefing: 142.44.220.135
*Generated via IPDebrief tools: Profile, History, Relationships, Neighbors, Actions*
---
**1. Risk Profile**
- Overall Risk Score: 40 (Moderate Risk)
- Provider: OVH (ASN 16276)
- Organization: Dmytro, Ahrefs Pte Ltd (OVH-CUST-281059685)
- Geolocation: Registered to Canada (CA), but geolocation data indicates Singapore (plausibility: false).
- Threat Indicators: No direct malicious activity detected (no indicators, blacklists, or campaigns).
---
**2. Network Context**
- Subnet: 142.44.220.0/24
- Subnet Abuse Density: 53.75% (High Abuse classification)
- Neighbor Risk: 100 neighbors in subnet; 95 rated Medium Risk, 4 rated Low Risk.
- Network Role: Hosting (firewalled, no exposed services).
---
**3. DNS & Services**
- PTR Hostname: `proxy-ca006-san135.ahrefs.net` (associated with Ahrefs, a legitimate SEO tool).
- DNSSEC: Validated.
- Open Ports: None detected.
- TLS/HTTP: No certificate or service banners identified.
---
**4. Historical Observations**
- Recent Activity:
- DNS resolution for `ahrefs.net` (June 2026).
- Subnet abuse density analysis (June 2026).
- Trend: No significant changes in risk score or threat indicators.
---
**5. Relationships**
- Linked Entities:
- Same network: OVH-CUST-281059685.
- DNS association: `proxy-ca006-san135.ahrefs.net` (Ahrefs).
- No correlated malicious IPs or campaigns.
---
**6. Security Recommendations**
- Firewall Rules:
- Block the IP via iptables/nftables/Cloudflare/AWS WAF:
```bash
iptables -A INPUT -s 142.44.220.135 -j DROP
nft add rule inet filter input ip saddr 142.44.220.135 drop
```
- Monitoring:
- Due to high subnet abuse density, monitor for lateral movement or network anomalies.
- Verify DNS association with Ahrefs (legitimate but part of a high-risk subnet).
---
**7. Summary**
This IP is part of a high-abuse subnet (53.75% abuse density) associated with Ahrefs. While no direct malicious activity is detected, the subnet's context warrants caution. Block the IP if not required for operations, and monitor for unusual behavior. The geolocation discrepancy (Canada vs. Singapore) may indicate registration errors or misconfigured data.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059685 |
| CIDR Block | 142.44.220.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca006-san135.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca006-san135.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 23% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 27% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 21% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:42 UTC |
| Last Seen | 2026-06-26 22:40:40 UTC |
| Profile Built | 2026-06-27 18:54:32 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 28 |
Full dossier details are available via our API.