IP INTELLIGENCE BRIEFING: 142.44.225.35
Executive Summary
IP address 142.44.225.35 operates as a Moderate Risk (Score: 50) infrastructure endpoint hosted within OVH cloud compute environment. The IP exhibits geographic inconsistencies, blacklist listings, and resides within a high-abuse density subnet. No active services currently detected on the endpoint.
Ownership & Network Classification
- ASN: 16276
- Organization: Dmytro, Ahrefs Pte Ltd
- Network: OVH-CUST-281059696 /142.44.225.0/24
- RIR: ARIN
- Infrastructure Type: CloudCompute (OVH hosting provider)
- Classification: Firewalled/No Services, Cloud hosting environment
Geolocation Analysis
- Registered Country: CA (Canada)
- Detected Location: Singapore
- Geographic Consensus: FALSE - Significant geographic inconsistency detected
- RTT Validation: 26ms observed vs. 112ms minimum expected for Canada-Singapore distance (5,598km). This indicates potential spoofing or geolocation data manipulation.
Threat Indicators
- Blacklist Status: Listed on 2 of 8 monitored blacklists
- DNSBL Entries: 2 total listings
- Abuse Confidence: Not explicitly scored
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Associated Campaigns: None identified
Network Neighborhood Assessment
- Subnet: 142.44.225.0/24
- Abuse Density: 0.6367 (63.67% - High Abuse classification)
- Active Siblings: 206 out of 256 total addresses
- Threat Siblings: 163 IPs classified as threats within subnet
- Inherited Risk: 25 points from neighborhood context
DNS & Service Profile
- PTR Hostname: proxy-ca017-san35.ahrefs.net
- Forward Resolution: proxy-ca017-san35.ahrefs.net
- Domain: ahrefs.net
- Email Authentication: SPF and DMARC records not configured
- Open Ports: None detected (firewalled)
- HTTP/HTTPS Services: Not responding
Historical Observation Timeline
- Total Signals: 17 observations recorded
- Most Recent: June 17, 2026
- Threat Persistence: Single threat observation detected
- Ownership Changes: None recorded
- Key Historical Signal: June 15, 2026 - Subnet abuse density confirmed at 0.6367 with High Abuse classification
Relationship Graph
- Total Relationships: 36 entities
- Primary Association: OVH-CUST-281059696 network segment (36+ connections)
- Network Type: Same Network relationships dominate
Recommended Actions
- Block List Recommendation: Consider blocking at perimeter firewall due to blacklist presence and high-risk neighborhood context
- Monitoring Priority: Medium - Geographic inconsistency warrants enhanced traffic analysis
- Investigation Focus: Verify legitimacy of ahrefs.net association given geographic and RTT anomalies
- Subnet Context: 63.67% abuse density suggests this /24 may be actively abused; correlate with known threat indicators
SOC Analyst Notes
The IP demonstrates moderate risk characteristics with notable geographic spoofing indicators (RTT violation). The subnet environment shows elevated abuse activity. Current lack of open services suggests either dormant infrastructure or aggressive firewalling. Recommend correlation with any inbound connection attempts and review of associated network traffic patterns.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059696 |
| CIDR Block | 142.44.225.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca017-san35.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca017-san35.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 25% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-21 14:56:12 UTC |
| Last Seen | 2026-06-28 13:27:54 UTC |
| Profile Built | 2026-06-29 07:33:25 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 24 |
Full dossier details are available via our API.