# IP Intelligence Briefing: 142.44.225.243/32
Classification: Moderate Risk Infrastructure Host
Date Generated: 2026-06-17
Analyst: IPDebrief Intelligence Team
---
## Executive Summary
IP address 142.44.225.243 is a cloud-hosted infrastructure endpoint registered to Ahrefs Pte Ltd (OVH infrastructure) with a moderate risk score of 50. The IP exhibits no direct threat indicators but is located within a high-abuse density subnet (142.44.225.0/24) and is listed on multiple DNSBL sources.
---
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 50 (Moderate Risk) |
| **ASN** | 16276 (OVH) |
| **Organization** | Dmytro, Ahrefs Pte Ltd |
| **Network Block** | 142.44.225.0/24 |
| **Geolocation** | CA/Singapore (INCONSISTENT) |
| **Infrastructure Type** | Cloud Compute / Hosting |
| **Service Status** | Firewalled / No Services |
---
## Threat Assessment
Direct Threat Indicators: None detected
- Known Attacker: False
- Tor Exit Node: False
- Spam Source: False
- Abuse Confidence Score: Null
Blacklist Status:
- DNSBL Listed: 2 of 8 total lists
- Max Severity: High
Geolocation Anomaly:
- Reported country: CA (Canada)
- Reported city: Singapore
- RTT Violation: 23ms observed vs 112ms minimum possible for 5,598km distance
- Geo validation flagged as implausible
---
## Neighborhood Analysis
Subnet: 142.44.225.0/24
- Abuse Density: 0.6641 (High Abuse Classification)
- Total Siblings: 256
- Active Siblings: 206
- Threat Siblings: 170
- Inherited Risk: 26
The subnet exhibits elevated abuse activity with 66% of peers classified as threat siblings.
---
## Historical Observations (19 Total)
Recent signal activity includes:
- 2026-06-17: 8 blacklist listings (2 active, high severity)
- 2026-06-15: Subnet abuse density signals (0.6641, high_abuse classification)
- 2026-06-15: Operator score 0.2174 (Minimal)
- 2026-06-15: Full profile scan with 6 dimensions covered
Threat Persistence: 0 days
Observation Count: 0 persistent threat observations
---
## Network Relationships
Primary DNS Association:
- proxy-ca017-san243.ahrefs.net (ahrefs.net domain)
Network Affiliations:
- Multiple relationships to OVH-CUST-281059696 network block
Total Relationships: 29 (15 network, 14 DNS associations)
---
## Recommended Actions
Monitoring:
- Monitor DNSBL listing status (2 of 8 lists)
- Track subnet abuse density changes in 142.44.225.0/24
- Validate geolocation consistency
Firewall Rules:
- No specific blocking recommendations due to lack of direct threat indicators
- Consider rate-limiting due to high-abuse subnet context
Investigation Priority: Low-Medium
*Reason: Infrastructure IP with legitimate ownership but elevated neighborhood risk*
---
Conclusion: This IP represents legitimate Ahrefs infrastructure hosting services, operating within an OVH cloud environment. The moderate risk rating stems primarily from subnet-level abuse characteristics rather than individual IP malicious activity. No immediate blocking is warranted, but continued monitoring of DNSBL status and neighborhood activity is recommended.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059696 |
| CIDR Block | 142.44.225.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca017-san243.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca017-san243.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 23% | 1 | 2 |
| geolocation | 34% | 2 | 3 |
| Overall | 23% | 10 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-23 12:21:53 UTC |
| Last Seen | 2026-06-28 20:52:21 UTC |
| Profile Built | 2026-06-29 02:54:32 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 22 |
Full dossier details are available via our API.