# IP Intelligence Briefing: 142.44.228.248/32
## Executive Summary
IP 142.44.228.248 is a cloud-hosting endpoint (OVH infrastructure) with moderate risk classification (40/100). While no direct threat indicators were detected on the endpoint itself, the IP resides within a subnet exhibiting high abuse density (0.6562) with 168 threat-identified sibling IPs out of 256 total addresses.
## Ownership and Network Classification
- Organization: Dmytro, Ahrefs Pte Ltd
- ASN: AS16276 (OVH SAS)
- Network: OVH-CUST-281059695
- CIDR Block: 142.44.228.0/24
- Infrastructure Type: CloudCompute (hosting provider)
- Classification: Cloud-hosted, firewalled (no active services detected)
## Geolocation Data
- Primary Location: Canada (QC region)
- Secondary Location: Singapore (data discrepancy noted)
- Accuracy Radius: 3,000km (indicating geolocation uncertainty)
- Note: Geo validation flagged as implausible; RIR registration incomplete
## Threat Profile
- Overall Risk Score: 40 (Moderate)
- Abuse Confidence: Not reported
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Blacklist Count: 0
- DNSBL Listings: 1 of 8 total lists
- Operator Score: 0.2174 (Minimal)
- Threat Persistence: 0 days observed
- Campaign Likelihood: None
## Network Services
- Open Ports: None detected
- DNS PTR: proxy-ca016-san248.ahrefs.net
- Forward Resolution: proxy-ca016-san248.ahrefs.net (forward confirmed: false)
- Hosted Domain: ahrefs.net
- Email Authentication: No SPF or DMARC records present
- HTTP/TLS: No active web services or certificates
## Neighborhood Analysis
- Subnet: 142.44.228.0/24
- Abuse Density: 0.6562 (HIGH)
- Classification: high_abuse
- Active Siblings: 205/256
- Threat Siblings: 168/256
- Risk Distribution: 0 high, 81 medium, 19 low risk neighbors
- Inherited Risk: 26/100
## Observation History
- Total Observations: 18
- Recent Signals (June 2026):
- Subnet abuse classification confirmed as high_abuse (0.6562 density)
- ASN AS16276 OVH SAS consistently identified
- Multiple port scanning events recorded
- No certificate matches or campaign correlations detected
- Operator score maintained at minimal level
## Network Relationships
- Primary Association: OVH-CUST-281059695 network (34 relationship entries)
- Network Classification: Consistent cloud hosting infrastructure
## Recommended Actions
- Firewall: Monitor inbound traffic; no specific blocking required at this time
- SOC Monitoring: Flag for enhanced monitoring due to high-abuse subnet context
- Threat Hunting: Investigate any outbound connections from this IP against known malicious destinations
- Subnet Context: Consider blocking or restricting traffic from the entire 142.44.228.0/24 subnet if threat activity is confirmed
## Conclusion
This IP represents a cloud-hosting endpoint with moderate individual risk but elevated contextual risk due to high-abuse subnet classification. No direct malicious indicators were detected, but the subnet environment warrants monitoring. The IP is associated with Ahrefs infrastructure and has been firewalled with no active services. SOC teams should monitor for lateral movement or command-and-control activity originating from this subnet.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059695 |
| CIDR Block | 142.44.228.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca016-san248.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca016-san248.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 25% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-21 20:59:12 UTC |
| Last Seen | 2026-06-28 15:08:10 UTC |
| Profile Built | 2026-06-29 03:12:46 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 25 |
Full dossier details are available via our API.