## IP INTELLIGENCE BRIEFING: 142.44.225.190/32
Classification: Moderate Risk | Status: Active
Executive Summary
IP address 142.44.225.190 resolves to OVH hosting infrastructure with a moderate risk score (50/100). While no direct threat indicators were identified, the subnet exhibits elevated abuse density (0.6875), and geolocation validation shows implausible routing parameters.
---
Ownership & Infrastructure
- Organization: Dmytro, Ahrefs Pte Ltd
- ASN: 16276 (OVH)
- CIDR Block: 142.44.225.0/24
- Network Role: Hosting infrastructure with firewalled/no services status
- DNS Records: ptrHostnames = proxy-ca017-san190.ahrefs.net (domain: ahrefs.net)
- Email Authentication: No SPF or DMARC records configured
Geolocation Analysis
- Claimed Location: Beauharnois, Quebec, Canada
- Validation Status: FAILED
- Critical Finding: RTT measurements indicate 26ms latency, which violates the minimum possible latency of 112ms for a 5,598km distance. This suggests the geolocation data is unreliable.
- Geolocation Confidence: geo_plausible = false
Threat Intelligence
- Risk Score: 50 (Moderate)
- Blacklist Status: Listed on 2 of 8 DNSBLs
- Known Threats: None identified
- Tor/Proxy/VPN: No
- Abuse Confidence: No quantified score available
Neighborhood Risk Assessment
- Subnet: 142.44.225.0/24
- Abuse Density: 0.6875 (HIGH)
- Active Siblings: 206 of 256 total IPs
- Threat Siblings: 176 IPs flagged as threats
- Risk Distribution: 97 medium, 3 low (0 high)
Control Plane & Routing
- BGP Prefix: 142.44.128.0/17
- Route Stability: FALSE (route changes detected)
- DNSSEC: Valid
- RPKI State: Not available
Observation History
- Total Observations: 22 signals over monitoring period
- Recent Activity: Multiple observations from June 2026
- Signal Types: Network classification, operator scoring, routing analysis, geolocation validation
- Persistence: Not persistently malicious
---
Recommended Actions
Immediate Mitigation:
```bash
# iptables
iptables -A INPUT -s 142.44.225.190 -j DROP
# nftables
nft add rule inet filter input ip saddr 142.44.225.190 drop
```
WAF/Cloud Protection:
- Cloudflare WAF: Block rule with expression `ip.src eq 142.44.225.190`
- AWS WAF: Add address 142.44.225.190/32 to rule set
- nginx: `deny 142.44.225.190;`
---
Analyst Notes
1. The high abuse density in the /24 subnet (0.6875) suggests this IP may be part of a broader compromised or misconfigured infrastructure.
2. Geolocation data should be treated as unreliable due to RTT violations.
3. DNSBL listings (2 of 8) indicate prior reputation issues.
4. No active services detected on this endpoint, suggesting it may be a dormant or firewalled system.
5. Consider blocking the entire /24 subnet if the threat profile warrants broader mitigation.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059696 |
| CIDR Block | 142.44.225.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca017-san190.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca017-san190.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 37% | 2 | 3 |
| Overall | 22% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:42 UTC |
| Last Seen | 2026-06-26 22:57:55 UTC |
| Profile Built | 2026-06-27 19:11:38 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 28 |
Full dossier details are available via our API.