# IP INTELLIGENCE BRIEFING: 142.44.228.192
## Executive Summary
IP 142.44.228.192 operates on OVH cloud infrastructure with a moderate risk profile (score: 50). The address resolves to afirewalled endpoint with no active services, hosted within the Ahrefs Pte Ltd customer network. While the IP itself shows no direct threat indicators, it resides in a high-abuse subnet (142.44.228.0/24) with 168 of 205 active siblings flagged as threats.
## Ownership and Infrastructure
- ASN: 16276 (OVH)
- Organization: Dmytro, Ahrefs Pte Ltd
- Network Name: OVH-CUST-281059695
- CIDR Block: 142.44.228.0/24
- Infrastructure Type: CloudCompute (OVH Hosting)
## Network Role Classification
- Primary Role: Firewalled / No Services
- Open Ports: None detected
- Cloud Provider: OVH (isCloud: true)
- Hosting Status: Active hosting environment (isHosting: true)
- Proxy/VPN/Tor: None detected
## Threat Indicators
- Abuse Confidence Score: Not scored
- Blacklist Count: 0
- Known Campaigns: None identified
- Known Attacker: False
- Spam Source: False
- Tor Exit Node: False
- DNSBL Listings: 2 of 8 lists
## Geolocation Analysis
- Primary Location: Singapore (with CA country code)
- RTT Anomaly: 25ms measured vs. 112ms minimum possible for 5,598km distance โ indicates geolocation inconsistency
- Accuracy Radius: 3,000km (low confidence)
- GeoValidation: Violation detected โ distance/time inconsistent
## Neighborhood Risk Assessment
- Subnet: 142.44.228.0/24
- Abuse Density: 0.6562 (HIGH)
- Subnet Classification: high_abuse
- Total Siblings: 256
- Active Siblings: 205
- Threat Siblings: 168
- Inherited Risk Score: 26
## DNS and Resolutions
- PTR Hostname: proxy-ca016-san192.ahrefs.net
- Forward Resolution: proxy-ca016-san192.ahrefs.net
- Domain: ahrefs.net
- Forward Confirmation: Inconsistent (forwardConfirmed: false)
- Email Auth: SPF and DMARC records not detected
## Temporal Analysis
- Ownership Changes: 0
- Threat Persistence: 0 days
- Threat Observation Count: 1
- Persistence: Not persistently malicious
## Recommended Actions
Based on the moderate risk score and high-abuse neighborhood classification:
Firewall Recommendations:
- iptables: `iptables -A INPUT -s 142.44.228.192 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 142.44.228.192 drop`
- nginx: `deny 142.44.228.192;`
- pfSense: `142.44.228.192/32`
- Cloudflare WAF: Block with expression `ip.src eq 142.44.228.192`
- AWS WAF: Add `142.44.228.192/32` to blocked addresses
## Intelligence Narrative
The IP 142.44.228.192 represents a low-to-moderate risk endpoint operating within a high-abuse OVH subnet. The address resolves to afirewalled infrastructure with no active services, reducing immediate exploitation potential. However, the subnet's high abuse density (65.62%) and 168 threat siblings suggest potential lateral movement risks. The geolocation inconsistency (Singapore vs. CA designation with RTT anomalies) warrants monitoring for potential spoofing activities. No direct malicious indicators were observed, but the inherited neighborhood risk and inconsistent geolocation data justify defensive blocking until further observation clarifies the endpoint's purpose.
Priority: MONITOR (moderate risk with neighborhood exposure)
Recommended Action: Block at perimeter, monitor for activity resumption
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059695 |
| CIDR Block | 142.44.228.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca016-san192.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca016-san192.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 32% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 25% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-23 12:21:55 UTC |
| Last Seen | 2026-06-28 20:54:32 UTC |
| Profile Built | 2026-06-29 02:56:47 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.