## IP Intelligence Briefing: 142.44.225.71/32
Classification: Moderate Risk | Risk Score: 40/100
Analysis Date: Current Intelligence Cycle
---
**Ownership & Network Context**
The IP address 142.44.225.71 belongs to OVH SAS (AS16276) under organization "Dmytro, Ahrefs Pte Ltd" within CIDR block 142.44.225.0/24. The subnet is registered with ARIN. The IP is classified as cloud infrastructure (OVH-CUST-281059696) with service purpose indicated as "Firewalled / No Services."
**Geolocation Discrepancies**
Geolocation data indicates country CA (Canada) with region QC, though the reported city is Singapore. This geographic inconsistency is flagged as implausible (geoPlausible: false). RTT measurements show 27ms average against a minimum possible 112ms for the reported distance, indicating potential geolocation spoofing or routing anomalies.
**DNS & Hostname Resolution**
Reverse DNS resolves to proxy-ca017-san71.ahrefs.net. The associated domain ahrefs.net shows no SPF, DMARC, or TXT record configurations. Forward DNS resolution is confirmed (count: 1).
**Service Exposure**
No open ports detected. The IP shows no active services, TLS certificates, or HTTP banners. This indicates either firewall-protected infrastructure or passive host configuration.
**Threat Indicators**
- Blacklist count: 0
- Known attacker flag: false
- Spam source flag: false
- Tor exit node: false
- No active threat campaigns detected
- Pulsedive risk: null
- DNSBL listed: 1 of 8 total lists
- Abuse confidence score: null
**Neighborhood Analysis**
The /24 subnet (142.44.225.0/24) exhibits elevated abuse characteristics:
- Abuse density: 56.25%
- Classification: high_abuse
- Threat siblings: 144 out of 256 total IPs
- Inherited risk score: 22
- Subnet risk profile shows 96 medium-risk neighbors out of 100 sampled
**Observation History**
19 total observations recorded. Recent signals (June 2026 timeframe) show:
- ASN: AS16276 ovh sas
- Geographic attribution: CA with confidence 0.75
- Operator score: 0.2174 (Minimal)
- Route stability: false
- No persistent malicious activity detected (threatPersistenceDays: 0)
**Recommendations**
The IP presents moderate risk with elevated neighborhood context but no active threat indicators. The geolocation inconsistency and DNSBL listing warrant monitoring. Given the firewalled nature and lack of open services, immediate blocking is not indicated. Recommended actions:
- Monitor for service activation
- Track geolocation consistency
- Review DNSBL listings for context
- Consider subnet-level monitoring due to high abuse density
---
Intel Summary: This is a cloud-hosted infrastructure IP (OVH) with moderate risk rating. While showing no active threats or open services, the subnet exhibits elevated abuse density. The geolocation inconsistency and DNSBL listing suggest warranting continued observation rather than immediate blocking.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059696 |
| CIDR Block | 142.44.225.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca017-san71.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca017-san71.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 23% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-21 20:59:11 UTC |
| Last Seen | 2026-06-28 15:03:48 UTC |
| Profile Built | 2026-06-29 03:07:06 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.