IP Intelligence Briefing: 142.44.225.178
Date: 2026-06-15
---
**1. Core Profile**
- Risk Score: 40 (Moderate Risk)
- Ownership:
- ASN: 16276 (OVH)
- Organization: Dmytro, Ahrefs Pte Ltd
- Netname: OVH-CUST-281059696
- Geolocation:
- Country: Canada (CA)
- City: Singapore (discrepancy noted; geo validation flags as implausible)
- Distance: 5,598 km (RTT 28.2ms, minimum possible RTT: 112ms)
- Network Role:
- Infrastructure: CloudCompute (OVH)
- Hosting: Yes
- Subnet: 142.44.225.0/24
---
**2. Threat Indicators**
- No direct malicious indicators (no abuse confidence, spam, or known attacker flags).
- DNS Associations:
- Linked to `proxy-ca017-san178.ahrefs.net` (Ahrefs Pte Ltd).
- Geo Validation:
- Plausibility: False (distance and RTT mismatch).
- Spoofing Risk: Possible misconfiguration or location spoofing.
---
**3. Observation History**
- Last 30 Days:
- Subnet Abuse Density: 53.52% (high_abuse classification).
- Threat Siblings: 137 IPs in the subnet flagged as threats.
- Active Siblings: 172 IPs (256 total).
- Behavioral Flags:
- RTT Anomalies: Observed RTT (28.2ms) significantly lower than minimum possible (112ms).
- Geo Plausibility: False (5598km distance vs. claimed Singapore location).
---
**4. Network Relationships**
- Connected Entities:
- Subnet: 142.44.225.0/24 (OVH-CUST-281059696).
- DNS: `proxy-ca017-san178.ahrefs.net` (Ahrefs).
- Provider: OVH (cloud infrastructure).
---
**5. Neighborhood Analysis**
- Subnet Risk:
- Abuse Density: 53.52% (high_abuse).
- Risk Distribution: 96 IPs rated medium, 4 low, 0 high.
- Neighboring IPs:
- 137 IPs in the subnet flagged as threats.
- 172 active IPs (256 total).
---
**6. Recommendations**
- Monitor Subnet: High abuse density suggests potential for lateral movement or compromised hosts.
- Verify Geolocation: Investigate spoofing or misconfiguration (5598km vs. Singapore claim).
- Check DNS Security: Ensure DNS records for `proxy-ca017-san178.ahrefs.net` are secure (SPF/DKIM).
- Network Segmentation: Consider isolating this subnet if it hosts sensitive assets.
Conclusion: While the IP itself is not malicious, its subnet exhibits high abuse density and geo validation issues. SOC teams should prioritize monitoring the subnet for anomalous activity and validate the IPโs geolocation and DNS configurations.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059696 |
| CIDR Block | 142.44.225.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca017-san178.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca017-san178.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 39% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 24% | 9 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-18 03:21:47 UTC |
| Last Seen | 2026-06-28 05:58:32 UTC |
| Profile Built | 2026-06-29 00:04:57 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 22 |
Full dossier details are available via our API.