Threat Intelligence Briefing: IP 142.44.228.186/32
Summary:
The IP address 142.44.228.186/32 has been associated with various network activities. The gathered data includes geolocation, domain associations, historical observation records, and neighborhood context. This intelligence briefing aims to provide a concise overview for SOC analysts to evaluate potential risks and take appropriate actions.
Geolocation:
- Country: United States
- Region: New York
- City: New York City
Historical Observation Data:
- Past Activity: The IP address has been observed engaging in HTTP and HTTPS traffic, indicating web-based interactions. There have been sporadic reports of unusual traffic patterns, particularly during off-peak hours. Notably, there have been no consistent patterns of malicious activity, but anomalies have been noted.
- Domain Associations: The IP address has been linked to domains primarily associated with legitimate web services, including news, e-commerce, and cloud service providers. There have been transient connections to domains flagged for hosting phishing schemes, though these links have not been persistent.
Relationships and Neighbors:
- Network Proximity: The IP address shares a subnet with several other IPs associated with a mix of residential and commercial services. There are connections to cloud services, suggesting shared infrastructure.
- Neighborhood Context: Neighboring IPs have exhibited a range of activities from benign web hosting to occasional instances of scanning and probing activities. No direct malicious activities have been attributed to the immediate subnet.
Threat Assessment:
- Risk Level: Moderate
- Reasoning: While there have been connections to phishing domains, these are transient and not indicative of sustained malicious behavior. The IP's association with legitimate services and the lack of consistent threat patterns suggest a low likelihood of ongoing exploitation. However, the noted anomalies warrant continued monitoring, particularly during atypical traffic periods.
Recommendations:
1. Monitoring: Implement enhanced monitoring of traffic from and to 142.44.228.186/32, focusing on anomaly detection during off-peak hours.
2. Alerts: Configure alerts for any traffic to known phishing domains originating from this IP.
3. Network Segmentation: Consider segmenting the network to isolate potentially risky traffic from this IP address.
Conclusion:
The IP address 142.44.228.186/32 is primarily associated with legitimate activities, with some transient connections to suspicious domains. While the risk is moderate, maintaining vigilance and monitoring for anomalies can help preempt any potential threats.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059695 |
| CIDR Block | 142.44.228.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca016-san186.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca016-san186.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 22% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-17 15:11:53 UTC |
| Last Seen | 2026-06-28 05:06:11 UTC |
| Profile Built | 2026-06-28 23:11:53 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 24 |
Full dossier details are available via our API.