# IP Intelligence Briefing: 142.44.228.25/32
Classification: Moderate Risk | Severity: Medium
Date: 2026-06-15
Intel Source: IPDebrief Network Intelligence
---
## Executive Summary
IP 142.44.228.25 operates from OVH cloud infrastructure in Beauharnois, Quebec, Canada. The address resolves to aforementioned Ahrefs proxy hostname and exhibits high-abuse neighborhood characteristics. No active malicious indicators detected, but the subnet environment warrants monitoring.
---
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 50 (Moderate) |
| **ASN** | 16276 (OVH SAS) |
| **Organization** | Dmytro, Ahrefs Pte Ltd |
| **Network** | OVH-CUST-281059695 |
| **Location** | Beauharnois, Quebec, Canada (CA) |
| **Infrastructure** | Cloud Compute / Hosting |
| **Network Role** | Firewalled / No Services |
---
## DNS & Service Analysis
- PTR Hostname: proxy-ca016-san25.ahrefs.net
- Domain: ahrefs.net
- Forward Resolution: Confirmed (1 host)
- Open Ports: None detected
- HTTP/TLS: No services responding
- CAA Records: Present
- DNSSEC: Valid
---
## Threat Indicators
- Known Attacker: No
- Spam Source: No
- Tor Exit: No
- Blacklist Count: 0 (profile) | 2 lists (control plane)
- Abuse Confidence: Not assessed
- Campaign Likelihood: None
- Cert Matches: 0
- Banner Matches: 0
---
## Neighborhood Intelligence
Subnet: 142.44.228.0/24
- Abuse Density: 0.6133 (High)
- Classification: high_abuse
- Inherited Risk Score: 24
- Total Siblings: 256
- Active Siblings: 193
- Threat Siblings: 157
Risk Distribution in /24:
- High Risk: 0
- Medium Risk: 81
- Low Risk: 19
---
## Observation History (Recent 20 Signals)
- Abuse Density Signal: 0.6133 (high_abuse classification)
- DNS Resolution: ahrefs.net with CAA records (confidence 0.80)
- ASN/ISP: AS16276, OVH SAS, proxy/VPN type (confidence 0.85)
- DNS Reputation: Minimal score (0.2174)
- Blacklist Status: Listed on 2+ lists with high severity
---
## Network Relationships
- Same Network: 38 relationships (OVH-CUST-281059695)
- Network Stability: Route changes observed in last 30 days (route not stable)
- BGP Prefix: 142.44.128.0/17
- RPKI State: Not assessed
---
## Security Recommendations
Immediate Actions
1. Monitor outbound traffic from this IP for data exfiltration patterns
2. Block inbound connections at perimeter firewall (no legitimate services detected)
3. Monitor for proxy/VPN abuse if this IP is used for outbound traffic
Firewall Rules (iptables/nftables)
```bash
# Block inbound (no legitimate services)
iptables -A INPUT -s 142.44.228.25 -j DROP
# Monitor outbound connections
iptables -A OUTPUT -d 142.44.228.25 -j LOG --log-prefix "OUTBOUND_142.44.228.25: "
```
WAF Rules (Cloudflare/AWS WAF)
- Add to watchlist for proxy/VPN traffic patterns
- Monitor for scanning activity from related IPs
Intelligence Note
The subnet exhibits high abuse density (0.6133) with 157 threat siblings out of 256 total IPs. This IP shares network infrastructure with the OVH customer network. While no direct malicious indicators are present, the neighborhood environment suggests elevated risk. Monitor for correlation with known Ahrefs scraping or SEO-related abuse campaigns.
---
End of Briefing
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059695 |
| CIDR Block | 142.44.228.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca016-san25.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca016-san25.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 22% | 1 | 2 |
| geolocation | 33% | 2 | 3 |
| Overall | 22% | 10 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-17 15:11:53 UTC |
| Last Seen | 2026-06-28 05:06:31 UTC |
| Profile Built | 2026-06-28 23:11:53 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 25 |
Full dossier details are available via our API.