IPDebrief

142.44.220.164

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING: 142.44.220.164/32

Date: 2026-06-18

Classification: MODERATE RISK / HIGH ABUSE NEIGHBORHOOD

---

## EXECUTIVE SUMMARY

IP 142.44.220.164 presents as moderate risk (score: 40/100) with a footprint in OVH cloud infrastructure associated with Ahrefs Pte Ltd. While the target IP itself shows no active threat indicators, the /24 subnet exhibits high abuse density (65.62%), with 168 of 170 active sibling IPs classified as threats.

---

## INFRASTRUCTURE PROFILE

---

## GEOLOCATION ANALYSIS

---

## THREAT INDICATORS

Services: No open ports detected. Firewall configuration active.

---

## NEIGHBORHOOD CONTEXT (CRITICAL)

The /24 subnet 142.44.220.0/24 demonstrates concerning abuse patterns:

The majority of active IPs in this subnet are flagged as threats, suggesting either compromised infrastructure or a shared hosting environment with elevated abuse risk.

---

## OBSERVATION HISTORY

The IP shows stable characteristics with no significant threat evolution over the observation period.

---

## RELATIONSHIPS

---

## SOC ACTION RECOMMENDATIONS

IMMEDIATE ACTIONS

1. Monitor Closely: While this IP itself is clean, block or rate-limit traffic from the entire 142.44.220.0/24 subnet due to 65.62% abuse density.

2. Verify Legitimacy: Confirm if Ahrefs has authorized operations from this subnet. Legitimate traffic should be verified against known Ahrefs endpoints.

3. Inspect Logs: Review inbound/outbound connections from this IP for any anomalous behavior despite clean threat indicators.

FIREWALL RULES

```bash

# Block high-risk subnet

iptables -A INPUT -s 142.44.220.0/24 -j DROP

# OR for rate limiting

iptables -A INPUT -s 142.44.220.0/24 -m limit --limit 5/min --limit-burst 10 -j ACCEPT

iptables -A INPUT -s 142.44.220.0/24 -j DROP

```

MONITORING PARAMETERS

---

## THREAT ASSESSMENT

Current Risk: MODERATE (Score: 40/100)

Neighborhood Risk: HIGH (65.62% abuse density)

Recommendation: BLOCK SUBNET OR IMPLEMENT STRICT RATE LIMITING

While IP 142.44.220.164 itself shows no active malicious behavior, the surrounding infrastructure demonstrates significant compromise indicators. Treat all traffic from this /24 subnet as potentially hostile until legitimacy is confirmed.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡จ๐Ÿ‡ฆ Canada
RegionQC
CitySingapore
Timezoneโ€”
Latitude45.51
Longitude-73.59

๐Ÿข Ownership & Registration

OrganizationDmytro, Ahrefs Pte Ltd
ASNAS16276
Network NameOVH-CUST-281059685
CIDR Block142.44.220.0/24
RIRARIN
CountrySingapore
Abuse Contactโ€”

๐ŸŒ DNS Intelligence

PTRproxy-ca006-san164.ahrefs.net
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesproxy-ca006-san164.ahrefs.net

๐Ÿ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAAPresent

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
28%
24
routing
13%
11
services
15%
22
ownership
15%
22
reputation
27%
13
geolocation
34%
23
Overall22%1015
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) โ€” 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Claimed geolocation contradicts RTT physics measurement

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-07 23:03:42 UTC
Last Seen2026-06-26 22:42:20 UTC
Profile Built2026-06-27 18:57:52 UTC
Data FreshnessLive
Signal Types21
Total Observations27
๐Ÿ” 21 signal types ยท 27 observations collected
This report is generated from 21+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.