IPDebrief

142.44.228.246

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 142.44.228.246

Classification: Moderate Risk / Cloud Infrastructure / High-Abuse Subnet

Date of Analysis: 2026-06-15

---

## Executive Summary

IP address 142.44.228.246 is a cloud-compute infrastructure endpoint hosted within OVH's customer network (OVH-CUST-281059695). The IP resolves to the ahrefs.net domain but presents no active services. While the specific endpoint carries a moderate risk score of 40, it resides within a subnet exhibiting high abuse density (0.6055), with 155 of 193 active siblings flagged as threats. The network association with Ahrefs Pte Ltd provides contextual legitimacy, yet the operational environment warrants defensive monitoring.

---

## Ownership and Infrastructure Profile

AttributeValue
**ASN**16276
**Organization**Dmytro, Ahrefs Pte Ltd
**Network Name**OVH-CUST-281059695
**CIDR Block**142.44.228.0/24
**RIR**ARIN
**Infrastructure Type**Cloud Compute
**ISP/Provider**OVH
**Registration Authority**RIPE NCC

The IP is classified as cloud hosting infrastructure. No proxy, VPN, Tor, or CDN indicators were detected. The control plane data indicates BGP routing through AS57866 and AS16276 with stable routing characteristics (isRouteStable: true).

---

## Geolocation Assessment

ParameterValueConfidence
**Country**Canada (CA)High
**Region**QuebecHigh
**City**SingaporeLow (3000km radius)
**Geo Source Count**1Low
**Geo Plausibility**FalseN/A

Geolocation consensus indicates Canada as the primary location, though a single source reported Singapore with 3000km accuracy radius, rendering the data unreliable. This discrepancy is common for cloud hosting environments using anycast or CDN-like routing.

---

## DNS and Hostname Resolution

ParameterValue
**PTR Hostname**proxy-ca016-san246.ahrefs.net
**Domain**ahrefs.net
**Forward Resolution**proxy-ca016-san246.ahrefs.net
**Forward Confirmed**False
**Email Auth (SPF/DMARC)**Not configured
**TXT Record Count**0

The IP resolves to an ahrefs.net PTR record indicating it is part of the Ahrefs infrastructure. However, forward resolution failed to confirm the PTR record, and no SPF or DMARC records are configured for the domain. This misalignment between reverse and forward DNS resolution is a common indicator of dynamically allocated cloud IPs.

---

## Network Classification and Reputation

MetricValue
**Risk Score**40 (Moderate)
**Abuse Confidence Score**N/A
**Blacklist Count**0
**DNSBL Listed**1 of 8 lists
**Known Attacker**False
**Tor Exit Node**False
**Spam Source**False
**Operator Score**0.4348 (Basic)

The IP carries a moderate risk score of 40 with no blacklists. One DNSBL listing was observed across eight total lists. The operator score of 0.4348 is classified as "Basic," indicating limited threat intelligence correlation.

---

## Neighborhood Analysis: 142.44.228.0/24

MetricValue
**Subnet Classification**High Abuse
**Abuse Density**0.6055
**Total Siblings**256
**Active Siblings**193
**Threat Siblings**155
**Inherited Risk**24

The subnet exhibits elevated abuse activity. Of 100 sampled neighbors:

Of 193 active siblings, 155 (80.3%) are classified as threats. This high abuse density suggests the network is commonly used for bulk hosting or potentially misconfigured infrastructure.

---

## Service and Port Scan Results

MetricValue
**Open Ports**None
**HTTP Title**N/A
**TLS Certificate**None
**Server Banner**None
**Service Purpose**Firewalled / No Services

No open ports, services, or web applications were detected on this specific IP address. The endpoint appears to be a passive infrastructure host with services either not running or filtered.

---

## Threat Indicators

IndicatorStatus
**Known Campaigns**None
**Cert Matches**0
**Banner Matches**0
**Correlated IPs**0
**Is Persistently Malicious**False
**Threat Persistence Days**0
**Threat Observation Count**1

No active threat campaigns or persistent malicious behavior was identified. A single threat observation was recorded, indicating limited historical threat activity.

---

## Historical Signal Analysis

25 observations were recorded as of 2026-06-15. Key historical signals include:

The IP's risk profile has remained stable over the observation period with no significant escalation or declassification events.

---

## Related Entities

39 relationships were identified, primarily:

---

## Recommended Actions

Based on the moderate risk profile and high-abuse subnet classification, the following defensive measures are recommended:

1. Monitor, Do Not Block: The IP does not exhibit

1. Monitor, Do Not Block: The IP does not exhibit active malicious behavior. However, the high-abuse subnet context warrants ongoing monitoring for connection attempts or outbound traffic anomalies.

2. Verify Legitimate Business Use: Confirm whether Ahrefs Pte Ltd has authorized legitimate use of this IP address for their infrastructure. The PTR record suggests association with the organization, but the subnet-level abuse density should be validated.

3. Review Network Traffic Patterns: If traffic is observed from this IP, analyze packet content for anomalies. The lack of open ports suggests this is a backend or passive host rather than a user-facing endpoint.

4. Correlate with Threat Intelligence Feeds: Cross-reference against internal threat intelligence databases for any historical correlation with known malicious campaigns or attacker infrastructure.

5. Monitor Subnet-Level Indicators: Given 80% of active siblings are flagged as threats, monitor the broader 142.44.228.0/24 subnet for coordinated activity patterns or campaign indicators.

6. Document for Baseline: Establish this IP as a known cloud-hosting endpoint with moderate risk characteristics for future incident triage and threat correlation workflows.

---

## Conclusion

IP 142.44.228.246 represents a cloud-compute infrastructure endpoint with moderate risk characteristics. While the specific IP shows no active malicious indicators, the high-abuse neighborhood context requires defensive vigilance. The IP's association with Ahrefs Pte Ltd suggests legitimate business use, but the subnet's abuse density warrants monitoring and correlation with organizational threat intelligence. No immediate blocking or escalation actions are required, but continued observation of traffic patterns and subnet-level activity is recommended.

Status: Monitor / Low Priority

Confidence Level: Medium (0.75 based on subnet abuse signals)

Next Review: 30 days or upon threat indicator escalation

---

*Report generated by IPDebrief Intelligence Platform. Data sourced from real-time observation and historical threat intelligence feeds.*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡จ๐Ÿ‡ฆ Canada
RegionQC
CitySingapore
Timezoneโ€”
Latitude45.51
Longitude-73.59

๐Ÿข Ownership & Registration

OrganizationDmytro, Ahrefs Pte Ltd
ASNAS16276
Network NameOVH-CUST-281059695
CIDR Block142.44.228.0/24
RIRARIN
CountrySingapore
Abuse Contactโ€”

๐ŸŒ DNS Intelligence

PTRproxy-ca016-san246.ahrefs.net
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesproxy-ca016-san246.ahrefs.net

๐Ÿ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAAPresent

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierTier 3 โ€” Basic operator with some routing infrastructure
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
26%
24
routing
27%
23
services
12%
22
ownership
30%
33
reputation
31%
13
geolocation
23%
22
Overall25%1217
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-16 08:56:00 UTC
Last Seen2026-06-28 03:15:44 UTC
Profile Built2026-06-29 03:21:45 UTC
Data FreshnessLive
Signal Types24
Total Observations29
๐Ÿ” 24 signal types ยท 29 observations collected
This report is generated from 24+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.