INTELLIGENCE BRIEFING: 142.44.225.207/32
Classification: Low Risk | Risk Score: 25/100
Date: 2026-06-26
Analyst: IPDebrief Intelligence Team
---
Executive Summary
IP address 142.44.225.207 is classified as Low Risk with a risk score of 25/100. The address is hosted on OVH cloud infrastructure (ASN 16276) under the organization "Dmytro, Ahrefs Pte Ltd." While the IP itself shows minimal direct threat indicators, the surrounding /24 subnet exhibits elevated abuse density, warranting contextual awareness.
Network Ownership & Infrastructure
- Provider: OVH (CloudCompute infrastructure)
- ASN: 16276 (OVH SAS)
- Organization: Dmytro, Ahrefs Pte Ltd
- CIDR Block: 142.44.225.0/24
- Geolocation: Canada (QC) / Singapore (inconsistent reporting)
- Infrastructure Type: Cloud Hosting
- DNS PTR: proxy-ca017-san207.ahrefs.net (ahrefs.net)
Threat Assessment
Direct threat indicators for this IP are minimal:
- Abuse Confidence Score: Not reported
- Known Attacker: False
- Spam Source: False
- Tor Exit Node: False
- Blacklist Status: Listed on 1 of 8 DNSBL feeds
- Known Campaigns: None identified
Neighborhood Analysis
The /24 subnet (142.44.225.0/24) shows mixed classification with inherited risk of 15:
- Abuse Density: 0.3906 (39% of active siblings flagged as threats)
- Active Siblings: 224/256
- Threat Siblings: 100
- Risk Distribution: 53 medium-risk, 47 low-risk neighbors
- Control Plane: Route stability issues detected (isRouteStable: false)
Historical Observations
Signal history indicates recent activity with 20 observations logged on 2026-06-26. Key temporal signals include:
- Subnet abuse density reporting at 0.3906
- ASN/geolocation signals from AlienVault OTX and Cymru
- DNS resolution confirmed for ahrefs.net with CAA records
- Operator score: 0.2174 (Minimal)
Related Entities
- 55 Relationship Links: Primarily network-level associations to OVH-CUST-281059696
- Campaign Correlation: No matching campaigns or correlated IPs identified
Recommended Actions
No specific firewall or mitigation rules are recommended for this IP at this time. The low risk score (25) and lack of direct threat indicators suggest standard monitoring is appropriate.
SOC Analyst Notes
1. Monitor Context: While this IP is low-risk, the subnet abuse density (39%) indicates potential collateral risk from neighboring addresses
2. Geolocation Inconsistencies: Report shows Canada (QC) with Singapore coordinatesβverify actual deployment location if needed
3. DNSBL Listing: One DNSBL listing detected; review if listing source is relevant to your threat landscape
4. Infrastructure Type: Cloud-hosted environment (OVH)βconsider tenant isolation implications for lateral threat movement
Status: No immediate blocking required. Maintain monitoring given neighborhood risk profile.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059696 |
| CIDR Block | 142.44.225.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca017-san207.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca017-san207.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 30% | 1 | 3 |
| geolocation | 31% | 2 | 3 |
| Overall | 23% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-11 15:04:03 UTC |
| Last Seen | 2026-06-27 19:32:08 UTC |
| Profile Built | 2026-06-28 19:42:50 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 26 |
Full dossier details are available via our API.