# IP Intelligence Briefing: 142.44.228.145/32
## Executive Summary
IP address 142.44.228.145 is a moderate-risk (40/100) cloud-hosted address operated by OVH under customer OVH-CUST-281059695. The IP resolves to aforementioned domain proxy-ca016-san145.ahrefs.net and is classified within a high-abuse subnet (142.44.228.0/24) with 68% abuse density.
## Profile Overview
| Attribute | Value |
|---|---|
| **Risk Score** | 40 (Moderate Risk) |
| **ASN** | 16276 (OVH) |
| **Organization** | Dmytro, Ahrefs Pte Ltd |
| **Network** | 142.44.228.0/24 |
| **Infrastructure** | Cloud Compute (OVH) |
| **DNSBL Status** | Listed on 1 of 8 threat feeds |
| **Open Ports** | None detected |
## Geographic Validation
The IP's geolocation data shows significant validation issues. The address is claimed to be located in Singapore (CA region), but RTT measurements indicate a distance of 5,597.9 km from the probe location. The minimum possible RTT for this distance is 112ms, yet observed RTT was only 27โ32msโa violation indicating the geolocation data is unreliable and the IP's actual location is unknown.
## Neighborhood Context
The /24 subnet 142.44.228.0/24 exhibits concerning abuse patterns:
- Abuse Density: 0.6797 (High)
- Active Siblings: 216 of 256
- Threat Siblings: 174 IPs flagged as threats
- Risk Distribution: 50 medium, 50 low, 0 high risk scores among sampled neighbors
This indicates the subnet is heavily utilized for potentially malicious activities, with the target IP inheriting an inherited risk score of 27 from neighborhood context.
## Historical Signals
Observation history shows 21 signals recorded between June 2026. Notable observations include:
- June 20: Cloud infrastructure classification confirmed (no CDN/VPN/proxy indicators)
- Recent observations show minimal operator scores (0.087โ0.30)
- No persistent malicious activity detected (threatPersistenceDays: 0)
- Ownership stability with zero changes recorded
## Relationship Graph
The IP has 51 relationship records, predominantly "Same Network" associations to OVH-CUST-281059695. No external organization links, certificates, or correlated campaigns were identified.
## Recommended Actions
While no automated recommendations were generated, the following defensive measures are advised:
Firewall Blocking Rules:
- iptables: `iptables -A INPUT -s 142.44.228.145 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 142.44.228.145 drop`
- nginx: `deny 142.44.228.145;`
- Cloudflare WAF: Block IP with expression `ip.src eq 142.44.228.145`
- AWS WAF: Add rule for CIDR 142.44.228.145/32
Assessment Notes:
- The DNSBL listing indicates prior reputation concerns
- Subnet-level abuse density warrants consideration of blocking the entire /24 if threat correlation exists
- No services detected on the IP, suggesting it may be dormant or firewalled
## Conclusion
This IP represents a moderate-risk asset within a high-abuse subnet. The geographic validation failure and DNSBL listing suggest potential misconfiguration or prior misuse. SOC teams should monitor traffic patterns and consider blocking at the network perimeter given the subnet's abuse density and the IP's blacklist status.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059695 |
| CIDR Block | 142.44.228.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca016-san145.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca016-san145.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 25% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-21 14:56:12 UTC |
| Last Seen | 2026-06-28 13:29:42 UTC |
| Profile Built | 2026-06-29 07:33:24 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 25 |
Full dossier details are available via our API.