# IP Intelligence Briefing: 142.44.225.75/32
## Executive Summary
IP address 142.44.225.75 is assigned to OVH host infrastructure (AS16276) under customer block OVH-CUST-281059696. The IP resolved to hostname proxy-ca017-san75.ahrefs.net. Risk assessment classified as Moderate Risk (score: 50) with high-abuse neighborhood classification.
## Ownership and Classification
- ASN: 16276 (OVH SAS)
- Organization: Dmytro, Ahrefs Pte Ltd
- Network Block: 142.44.225.0/24
- Infrastructure Type: CloudCompute / Hosting
- Provider Classification: OVH cloud provider
## Geolocation Analysis
Geolocation data presents significant inconsistencies:
- Claimed Location: Canada (Quebec), but geolocation sources indicate Singapore
- RTT Violation: Observed RTT of 27ms violates minimum possible 112ms for 5,598km distance
- GeoValidation: geoPlausible flag set to false, indicating unreliable location data
- Accuracy Radius: 3,000km due to conflicting source data
## Threat Intelligence Indicators
- Abuse Confidence: Not explicitly scored
- Blacklist Status: Listed on 2 of 8 DNSBL lists
- Threat Indicators: No known attacker indicators, no Tor exit, no known campaigns
- Known Spam Source: No classification
- Control Plane: Operator score of 0.2174 labeled "Minimal"
## Neighborhood Analysis
The /24 subnet (142.44.225.0/24) exhibits high abuse characteristics:
- Abuse Density: 0.6953 (High)
- Subnet Classification: high_abuse
- Threat Siblings: 178 out of 256 active IPs (69.5%)
- Inherited Risk Score: 27
- Risk Distribution: 39 medium risk, 61 low risk, 0 high risk neighbors
## DNS Analysis
- PTR Record: proxy-ca017-san75.ahrefs.net
- Forward Resolution: 1 hostname (proxy-ca017-san75.ahrefs.net)
- Domain: ahrefs.net
- Email Authentication: No SPF or DMARC records configured
- Forward Confirmation: False
## Service Analysis
- Open Ports: None detected (firewalled)
- TLS Certificate: Not detected
- HTTP Title: Not detected
- Services Purpose: Firewalled / No Services
## Historical Observations
Recent signal history (2026-06-20) shows:
- Consistent high-abuse classification across multiple observations
- ASN 16276 OVH confirmed in network role signals
- Multiple geolocation sources with conflicting data
- Abuse density maintained at 0.6953
## Recommended Actions
Based on the moderate risk classification and high-abuse neighborhood, consider:
- Monitor for suspicious outbound traffic patterns
- Block or rate-limit if threat indicators escalate
- Review DNSBL listings for specific blocking requirements
- Investigate correlation with other IPs in 142.44.225.0/24 subnet
## Risk Assessment
The IP presents moderate risk primarily due to:
1. High-abuse neighborhood (69.5% threat siblings)
2. DNSBL listings (2 of 8 lists)
3. Unreliable geolocation data suggesting potential spoofing
4. Lack of email authentication records
No immediate active threat indicators detected. Recommend ongoing monitoring.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059696 |
| CIDR Block | 142.44.225.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca017-san75.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca017-san75.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 22% | 1 | 2 |
| geolocation | 33% | 2 | 3 |
| Overall | 21% | 10 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-21 20:59:11 UTC |
| Last Seen | 2026-06-28 15:04:25 UTC |
| Profile Built | 2026-06-29 09:10:27 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 25 |
Full dossier details are available via our API.