IP Intelligence Briefing: 142.44.228.45
*Generated via IPDebrief Threat Intelligence Platform*
---
**Core Profile**
- Risk Assessment: Low Risk (Risk Score: 30) | No active threats or abuse indicators.
- Ownership: Registered to Ahrefs Pte Ltd (OVH customer, ASN 16276).
- Geolocation:
- Country: Canada (CA) | Region: QC | City: Singapore (conflict detected).
- Geoplusibility: False (RTT discrepancy: 25ms vs. expected 112ms for 5,598km).
- Network Role: Cloud infrastructure (OVH-hosted, no public services).
---
**Threat Context**
- No Direct Threats: No malware, phishing, or malicious campaign indicators.
- Subnet Risk:
- /24 subnet (142.44.228.0/24) has high abuse density (60.16%).
- 154/256 IPs in the subnet are flagged as threats.
- 185 active IPs in the subnet, with 24 inherited risk from neighboring IPs.
---
**Observation History**
- Recent Activity:
- RTT anomalies (25ms vs. expected 112ms for distance).
- No DNS or TLS anomalies detected.
- Stable BGP routing (no recent route changes).
---
**Network Relationships**
- Linked Entities:
- Same network: OVH-CUST-281059695 (shared /24 subnet).
- DNS: Resolves to proxy-ca016-san45.ahrefs.net (Ahrefs domain).
- No direct ties to known malicious domains or organizations.
---
**Neighbor Analysis**
- Subnet Summary:
- 100+ neighboring IPs in the subnet.
- 80% of neighbors classified as medium/high risk.
- Key IPs: 142.44.228.0β4 show elevated risk (40β50 score).
- Abuse Density: Subnet is categorized as high_abuse, suggesting potential compromise or misconfigured infrastructure.
---
**SOC Actionable Insights**
1. Monitor Subnet: Investigate high-risk neighbors (e.g., 142.44.228.0β4) for lateral movement or shared vulnerabilities.
2. Verify Geolocation: Confirm IP location discrepancy (Canada vs. Singapore) to rule out spoofing or misconfigured routing.
3. Review DNS: Ensure Ahrefsβ DNS (proxy-ca016-san45.ahrefs.net) is legitimate and not abused.
4. Check Cloud Provider: Engage OVH to validate network security practices for this subnet.
Conclusion: While the IP itself is low risk, its subnetβs high abuse density warrants closer scrutiny. Prioritize monitoring and validation of the broader network environment.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059695 |
| CIDR Block | 142.44.228.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca016-san45.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca016-san45.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 2 β Moderate operator sophistication with routing hygiene |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 23% | 2 | 4 |
| routing | 22% | 3 | 4 |
| services | 12% | 2 | 2 |
| ownership | 22% | 3 | 3 |
| reputation | 27% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 23% | 13 | 19 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:03:43 UTC |
| Last Seen | 2026-06-26 23:12:30 UTC |
| Profile Built | 2026-06-27 19:27:52 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 32 |
Full dossier details are available via our API.