# IP Intelligence Briefing: 142.44.228.33/32
Classification: Moderate Risk | Date of Analysis: Current
Report ID: IP-142.44.228.33-BRIEF
---
## Executive Summary
IP 142.44.228.33 is assigned to OVH hosting infrastructure with a moderate risk score of 50. The address is hosted under the organization "Dmytro, Ahrefs Pte Ltd" (ASN 16276) within the 142.44.228.0/24 CIDR block in Beauharnois, Quebec, Canada. While the IP itself shows no active threat indicators, the residential subnet demonstrates elevated abuse density characteristics.
---
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 50/100 (Moderate) |
| **ASN** | 16276 |
| **Organization** | Dmytro, Ahrefs Pte Ltd |
| **Netname** | OVH-CUST-281059695 |
| **Location** | Beauharnois, QC, Canada |
| **RIR** | ARIN |
| **Network Role** | Hosting Provider |
| **Infrastructure Type** | Cloud Hosting |
---
## Threat Intelligence Indicators
- Abuse Confidence: No current threat indicators identified
- Blacklist Status: 0 blacklists (control plane shows 2 DNSBL listings out of 8 total checks)
- Known Campaigns: None associated
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
Historical Signal Summary: 21 observations recorded. Recent activity on 2026-06-28 indicated high-severity listings with 8 total blacklist references. Ownership remains stable with zero ownership changes recorded.
---
## DNS Analysis
| Field | Value |
|---|---|
| **PTR Hostname** | proxy-ca016-san33.ahrefs.net |
| **Forward Resolution** | proxy-ca016-san33.ahrefs.net |
| **Domain** | ahrefs.net |
| **Forward Confirmation** | Not confirmed |
| **SPF/DMARC** | Not configured |
---
## Neighborhood Analysis (142.44.228.0/24)
- Abuse Density: 0.6719 (High Abuse classification)
- Total Siblings: 256
- Active Siblings: 210
- Threat Siblings: 172
- Inherited Risk: 26/100
Risk Distribution Within Subnet:
- High Risk: 0
- Medium Risk: 58
- Low Risk: 42
---
## Control Plane Assessment
- BGP Prefix: 142.44.128.0/17
- Route Stability: Not stable
- RPKI State: Not verified
- Route Changes (30-day): 0
- DNSSEC: Valid
- CAA Records: Present
---
## Recommended Security Actions
Status: Firewall rules generated for risk mitigation. No specific threat-based blocking required at this time.
Recommended Rules:
- iptables: `iptables -A INPUT -s 142.44.228.33 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 142.44.228.33 drop`
- nginx: `deny 142.44.228.33;`
- pfSense: `142.44.228.33/32`
- Cloudflare WAF: Block with expression `ip.src eq 142.44.228.33`
- AWS WAF: Include address `142.44.228.33/32` in rule set
---
## Intelligence Assessment
The IP 142.44.228.33 operates within OVH hosting infrastructure and resolves to an ahrefs.net proxy hostname, consistent with legitimate web infrastructure. No active threat indicators or malicious behavior have been observed. However, the parent subnet (142.44.228.0/24) exhibits high abuse density with 172 threat siblings among 256 total addresses, indicating potential collateral risk from neighboring IPs.
Recommendation: Monitor for changes in behavior or threat indicators. Apply precautionary blocking if threat context emerges. No immediate action required based on current profile.
---
*Report generated from IPDebrief intelligence platform. All data sourced from live network scans and threat intelligence feeds.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059695 |
| CIDR Block | 142.44.228.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca016-san33.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca016-san33.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 22% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-15 20:46:46 UTC |
| Last Seen | 2026-06-28 02:42:47 UTC |
| Profile Built | 2026-06-28 20:48:06 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 24 |
Full dossier details are available via our API.