# IP Intelligence Briefing: 142.44.225.205/32
## Executive Summary
IP 142.44.225.205 is a cloud-hosted address associated with OVH infrastructure, resolving to proxy infrastructure for the ahrefs.net domain. The IP carries a moderate risk score of 40 and is hosted within a subnet exhibiting high abuse density.
## Infrastructure Profile
- Organization: Dmytro, Ahrefs Pte Ltd
- ASN: 16276 (OVH)
- Netname: OVH-CUST-281059696
- CIDR Block: 142.44.225.0/24
- Registration RIR: ARIN
- Infrastructure Type: CloudCompute / Hosting
- Service Purpose: Firewalled / No Services Detected
## Geolocation & Network Data
- Country: CA (Canada)
- Region: QC (Quebec)
- City: Singapore (reported; accuracy radius 3000km)
- DNS PTR: proxy-ca017-san205.ahrefs.net
- Forward Resolution: proxy-ca017-san205.ahrefs.net (unconfirmed)
- DNSSEC Valid: true
## Risk Assessment
- Overall Risk Score: 40 (Moderate Risk)
- Abuse Confidence Score: Not available
- Blacklist Count: 0
- DNSBL Listed: 1 of 8 total lists
- Campaign Correlation: None identified
- Threat Indicators: No direct indicators (not Tor exit, not known attacker, not spam source)
## Neighborhood Analysis
The /24 subnet (142.44.225.0/24) shows elevated abuse characteristics:
- Abuse Density: 0.6641 (High Abuse Classification)
- Total Siblings: 256
- Active Siblings: 206
- Threat Siblings: 170
- Inherited Risk Score: 26
- Risk Distribution in Subnet: 53 Medium Risk, 47 Low Risk
## Control Plane Observations
- BGP Prefix: 142.44.128.0/17
- Origin ASN: 16276
- Route Stability: Unstable
- Operator Score: 0.2174 (Minimal)
- DNSSEC Validation: Valid
- CAAA Records: Present
## Historical Observations
Analysis of 20 signal observations indicates:
- Recent classification consistently shows "high_abuse" subnet designation
- Abuse density maintained at 0.6641 across recent observations
- One historical observation (2026-06-14) shows geolocation with country CA and region QC
- No persistent malicious behavior detected
## Threat Context
- Campaign Likelihood: None
- Certificate Matches: 0
- Banner Matches: 0
- Correlated IPs: 0
- Known Campaigns: None identified
## Recommended Actions
Based on the moderate risk profile, the following firewall rules are recommended:
iptables:
```
iptables -A INPUT -s 142.44.225.205 -j DROP
```
nftables:
```
nft add rule inet filter input ip saddr 142.44.225.205 drop
```
nginx:
```
deny 142.44.225.205;
```
Cloudflare WAF:
```json
{
"description": "Block 142.44.225.205 โ IPDebrief risk score 40",
"action": "block",
"filter": {"expression": "ip.src eq 142.44.225.205"}
}
```
AWS WAF:
```json
{
"Addresses": ["142.44.225.205/32"],
"Description": "IPDebrief risk 40"
}
```
## Intelligence Assessment
IP 142.44.225.205 represents proxy infrastructure for ahrefs.net hosted on OVH cloud infrastructure. While no direct threat indicators are present, the subnet exhibits elevated abuse density with 170 of 256 sibling IPs flagged as threats. The IP should be evaluated in the context of its network neighborhood for potential lateral threat indicators. No evidence of persistent malicious activity or campaign association was identified.
---
*Report generated by IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059696 |
| CIDR Block | 142.44.225.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca017-san205.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca017-san205.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 20% | 2 | 3 |
| ownership | 12% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 21% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-12 15:46:38 UTC |
| Last Seen | 2026-06-27 21:31:41 UTC |
| Profile Built | 2026-06-28 15:37:19 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 24 |
Full dossier details are available via our API.