# IP Intelligence Briefing: 142.44.220.35/32
Date: 2026-06-26
Classification: Moderate Risk
Prepared For: SOC Team
## Executive Summary
IP address 142.44.220.35 is a moderate-risk (score: 40) OVH-hosted address associated with ahrefs.net infrastructure. The IP resides within a high-abuse density subnet (142.44.220.0/24) showing significant abuse correlation. While the IP itself shows no direct threat indicators, neighborhood context and geolocation anomalies warrant monitoring.
---
## Infrastructure Profile
Ownership & Classification:
- ASN: 16276 (OVH)
- Organization: Dmytro, Ahrefs Pte Ltd
- Network Block: 142.44.220.0/24
- Provider: OVH Hosting Infrastructure
- Network Role: Firewalled / No Services
Geolocation:
- Reported Country: CA (Canada)
- Reported Region/City: QC / Singapore
- Consensus: Geo-plausible: false
- Accuracy Radius: 3000km
- Violation: RTT 21.0ms < minimum possible 112.0ms for 5598km distance
DNS Resolution:
- PTR Hostname: proxy-ca006-san35.ahrefs.net
- Domain: ahrefs.net
- Forward Resolution: 1 confirmed hostname
- Email Auth: No SPF/DMARC records detected
---
## Threat Indicators
Current Status:
- Risk Score: 40/100 (Moderate Risk)
- Abuse Confidence: Not scored
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0
- Threat Feeds: None detected
Service Status:
- Open Ports: None detected
- HTTP/TLS Services: None active
- Service Purpose: Firewalled / No Services
---
## Neighborhood Analysis
Subnet Context (142.44.220.0/24):
- Abuse Density: 0.6328 (High Abuse)
- Total Siblings: 256
- Active Siblings: 195
- Threat Siblings: 162
Risk Distribution:
- High Risk: 0
- Medium Risk: 87 (34%)
- Low Risk: 13 (5%)
The subnet shows significant abuse correlation, with 63% of active IPs flagged as threats. This elevated neighborhood risk suggests potential infrastructure sharing or compromised hosting environment.
---
## Historical Observations
Observation Count: 26 signals recorded
Recent Activity:
- 2026-06-26: Cloud compute classification (OVH), hosting provider confirmed
- 2026-06-22: Service scanning activity detected
- Ownership Changes: 0 (stable ownership)
- Threat Persistence: 0 days (not persistently malicious)
Temporal Analysis: The IP shows no persistent malicious behavior, with ownership remaining stable across observation periods.
---
## Relationship Graph
Total Relationships: 70
Primary Associations:
- Same Network: OVH-CUST-281059685 (multiple references)
- External Correlations: None detected (no external subnets, hostnames, or certificate links)
The IP exists primarily within the OVH customer network with no detected external relationships.
---
## Recommended Actions
Firewall Blocking Rules:
| System | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 142.44.220.35 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 142.44.220.35 drop` |
| nginx | `deny 142.44.220.35;` |
| pfSense | `142.44.220.35/32` |
| Cloudflare WAF | Block IP with risk score 40 |
| AWS WAF | Add 142.44.220.35/32 to block list |
Risk Assessment:
- Recommendation: Block (probability-based)
- Disclaimer: Recommendations should be combined with other signals before taking action
---
## Intelligence Narrative
The target IP 142.44.220.35 presents moderate risk within a high-abuse hosting environment. The address belongs to OVH's customer infrastructure block 142.44.220.0/24, which demonstrates elevated abuse density (63.28%) with 162 of 256 sibling IPs flagged as threats. This neighborhood context suggests potential shared infrastructure misuse or compromised co-located services.
Geolocation anomalies indicate the IP may be misconfigured or spoofed, showing a Canada-registered ASN with Singapore-associated DNS records and RTT measurements inconsistent with physical distance. The DNS hostname (proxy-ca006-san35.ahrefs.net) associates the IP with the ahrefs.net domain, though no active web services or email authentication records were detected.
No direct threat indicators were observedβno open ports, no blacklist entries, no known campaigns, and no persistent malicious activity. However, the high-abuse subnet environment and geolocation discrepancies warrant monitoring. The IP should be blocked at perimeter controls, with continued observation of the broader subnet for emerging threat patterns.
---
End of Briefing
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059685 |
| CIDR Block | 142.44.220.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca006-san35.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca006-san35.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 32% | 2 | 3 |
| services | 18% | 2 | 2 |
| ownership | 29% | 3 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 29% | 12 | 18 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:03:42 UTC |
| Last Seen | 2026-06-26 22:49:22 UTC |
| Profile Built | 2026-06-27 19:02:32 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 31 |
Full dossier details are available via our API.