# IP INTELLIGENCE BRIEFING: 142.44.225.43/32
Date: 2026-06-20
Classification: Moderate Risk (Score: 40/100)
Provider: OVH (ASN: 16276)
## EXECUTIVE SUMMARY
IP 142.44.225.43 is a cloud-hosted IP address allocated to Dmytro, Ahrefs Pte Ltd under OVH infrastructure. The address exhibits moderate risk with elevated neighborhood abuse density. No active threat indicators detected at this time, but geo-validation anomalies and high subnet abuse concentration warrant monitoring.
## OWNERSHIP & INFRASTRUCTURE
- Organization: Dmytro, Ahrefs Pte Ltd
- AS Number: 16276 (OVH)
- CIDR Block: 142.44.225.0/24
- Network Role: CloudCompute / Hosting
- PTR Hostname: proxy-ca017-san43.ahrefs.net
- Domain: ahrefs.net
## GEOLOCATION & VALIDATION
- Reported Location: CA/QC (claimed), Singapore (inconsistent)
- RTT Anomaly Detected: Observed RTT 27ms vs minimum possible 112ms for 5598km distance (5 violations)
- GeoPlausible: False
- Accuracy: 3000km radius
- DNSSEC: Validated
## THREAT POSTURE
- Risk Score: 40/100 (Moderate Risk)
- Blacklist Count: 0
- DNSBL Listed: 1 of 8 lists
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Campaign Association: None
## NEIGHBORHOOD ANALYSIS (142.44.225.0/24)
- Abuse Density: 0.7227 (High)
- Classification: high_abuse
- Total Siblings: 256
- Active Siblings: 223
- Threat Siblings: 185
- Inherited Risk: 28
The subnet shows significant abuse concentration with 72% abuse density. This IP carries inherited risk from neighborhood context.
## SERVICE POSTURE
- Open Ports: None detected
- HTTP/TLS Services: No active services
- Certificate Status: None
- Connection Type: Firewalled / No Services
## OBSERVATION HISTORY
Recent observations (2026-06-20):
- Abuse density signal: 0.7227 (high_abuse)
- Ownership stability: No changes
- Threat persistence: 0 days
- Total threat observations: 1
## RECOMMENDED ACTIONS
Firewall Recommendations:
- Block at network perimeter
- iptables: `iptables -A INPUT -s 142.44.225.43 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 142.44.225.43 drop`
- Cloudflare WAF: Block (risk score 40)
- AWS WAF: Add to block list (142.44.225.43/32)
## INTELLIGENCE ASSESSMENT
This IP addresses a legitimate cloud hosting provider (OVH) with ahrefs.net infrastructure. While no active malicious indicators exist, the high-abuse classification of the /24 subnet (185 threat siblings out of 256) suggests potential for abuse. The geolocation validation failure (RTT discrepancy) indicates possible misconfiguration or spoofing. No immediate threat action required, but monitor for emergence of threat indicators or increased neighborhood abuse activity.
Priority: LOW-MEDIUM
Recommended Action: Monitor, consider blocking if additional threat signals emerge
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059696 |
| CIDR Block | 142.44.225.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca017-san43.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca017-san43.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 32% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 32% | 1 | 3 |
| geolocation | 40% | 2 | 3 |
| Overall | 25% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-23 18:28:30 UTC |
| Last Seen | 2026-06-28 22:17:28 UTC |
| Profile Built | 2026-06-29 04:20:19 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 23 |
Full dossier details are available via our API.