IP Intelligence Briefing: 142.44.225.1
Date: June 17, 2026
---
**1. Core Profile**
- Risk Score: 50 (Moderate Risk)
- Provider: OVH (ASN 16276)
- Organization: Dmytro, Ahrefs Pte Ltd (OVH-CUST-281059696)
- Geolocation:
- Country: Canada (CA)
- City: Singapore (conflicting with geoplus RTT analysis).
- Accuracy Radius: 3,000 km (low confidence).
- Network Role: Cloud compute infrastructure (hosting, no residential/mobile).
- Threat Indicators: No malicious indicators, spam, or known attacker activity.
---
**2. Observation History**
- Recent Activity (Last 30 Days):
- Geolocation: Confirmed as Canada (CA) with inconsistent city data (Singapore).
- Network Stability: Route stability score of 0.2174 (Minimal operator risk).
- Threat Signals: No persistent malicious activity; 0 threat observations.
- Key Anomalies:
- RTT Discrepancy: 27ms latency for 5,598km distance (implies proxy/VPN or geolocation error).
- DNSSEC Valid: True; CAA records present.
---
**3. Network Relationships**
- Subnet: 142.44.225.1/24 (OVH network).
- Linked Entities:
- Organization: Ahrefs Pte Ltd (cloud hosting).
- DNS: PTR hostname `proxy-ca017-san1.ahrefs.net` (linked to `ahrefs.net`).
- BGP: Prefix `142.44.128.0/17` (OVH).
---
**4. Neighborhood Analysis**
- Subnet Abuse Density: 59.38% (High abuse classification).
- Neighbor Risk Distribution:
- Medium Risk: 96 IPs (avg. score 50).
- Low Risk: 4 IPs (avg. score 40).
- Threat Siblings: 152 risky IPs in the subnet.
- Actionable Insight: Monitor adjacent IPs for potential lateral movement or compromised hosts.
---
**5. Recommendations**
1. Subnet Monitoring:
- Investigate high-abuse subnet (142.44.225.0/24) for correlated threats.
- Use IDS/IPS to detect anomalies in traffic patterns.
2. Geolocation Verification:
- Validate IP's true location (Singapore vs. Canada) via alternative geolocation sources.
3. DNS & BGP Checks:
- Confirm DNSSEC and CAA configurations for `ahrefs.net` to prevent spoofing.
4. Firewall Rules:
- Restrict traffic to trusted subnets; consider blocking high-risk neighbors.
---
Conclusion:
142.44.225.1 is a cloud-hosted IP with moderate risk, but its subnet (142.44.225.0/24) exhibits high abuse density. While the IP itself shows no direct malicious activity, the surrounding network environment warrants further scrutiny. SOC teams should prioritize monitoring the subnet and validating the IPโs geolocation to mitigate potential risks.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059696 |
| CIDR Block | 142.44.225.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca017-san1.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca017-san1.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 15% | 2 | 2 |
| reputation | 27% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 21% | 9 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:42 UTC |
| Last Seen | 2026-06-26 22:53:33 UTC |
| Profile Built | 2026-06-27 19:07:03 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 24 |
Full dossier details are available via our API.