## IP INTELLIGENCE BRIEFING: 142.44.228.71/32
Classification: LOW RISK
Date: 2026-06-25
Analysis: Complete profile review
---
EXECUTIVE SUMMARY
IP 142.44.228.71 is classified as low risk (score: 25/100) and represents an OVH cloud compute infrastructure asset associated with Ahrefs (ahrefs.net). No active threat indicators detected. The IP operates within a moderate-abuse-density subnet (0.4375) containing 112 malicious siblings.
---
INFRASTRUCTURE PROFILE
| Attribute | Value |
|---|---|
| **Provider** | OVH (ASN 16276) |
| **Organization** | Dmytro, Ahrefs Pte Ltd |
| **Network** | 142.44.228.0/24 |
| **Infrastructure Type** | CloudCompute / Hosting |
| **Status** | Firewalled / No Services Detected |
---
GEOLLOCATION ANALYSIS
Reported Location: Canada (QC)
Validation Status: โ ๏ธ GEOLOGICAL DISCREPANCY DETECTED
- GeoPlausible: False
- RTT Violation: 25ms observed vs 112ms minimum for 5598km distance
- Average RTT: 30.4ms
- Distance Discrepancy: 5597.9km
Assessment: Reported Canada location is geographically implausible. IP likely located in different region than advertised.
---
DNS & HOSTING
- PTR Record: proxy-ca016-san71.ahrefs.net
- Domain: ahrefs.net
- Forward Resolution: Confirmed (1 hostname)
- HTTP Services: None detected (firewalled)
- TLS Certificates: None
- Email Auth: SPF/DMARC not configured on domain
---
THREAT INTELLIGENCE
| Indicator | Status |
|---|---|
| Known Attacker | No |
| Tor Exit Node | No |
| Proxy/VPN | No |
| Spam Source | No |
| Blacklist Count | 0 |
| DNSBL Listed | 1/8 lists |
| Active Threats | None |
| Campaign Association | None |
---
SUBNET CONTEXT (142.44.228.0/24)
- Total Siblings: 256 IPs
- Active Siblings: 228
- Threat Siblings: 112 (43.75% abuse density)
- Risk Distribution: 64 medium-risk, 36 low-risk, 0 high-risk
- Subnet Classification: Mixed
---
OBSERVATION HISTORY
Total Signals: 21 observations
Latest Observation: 2026-06-25T22:19:46 UTC
Threat Persistence: 0 days
Key Observations:
- Network classification stable (OVH cloud compute)
- Abuse density consistent at 0.4375
- No threat signal evolution observed
---
RELATIONSHIP MAPPING
- Primary Network: OVH-CUST-281059695
- Connection Type: Cloud infrastructure
- Related Entities: 54 relationships identified (network-focused)
---
SECURITY RECOMMENDATIONS
Current Risk: LOW โ No immediate blocking required
Actions: Monitor subnet 142.44.228.0/24 for emerging threats
Firewall Rules: Not recommended (below threshold)
---
INTELLIGENCE NOTES
1. The IP is part of OVH hosting infrastructure with legitimate association to ahrefs.net
2. Significant geolocation discrepancy requires operational awareness
3. Subnet abuse density warrants periodic monitoring despite low-risk target
4. No active malicious activity observed against this IP
Classification: LOW RISK
Recommended Action: Monitor
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059695 |
| CIDR Block | 142.44.228.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca016-san71.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca016-san71.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 37% | 2 | 3 |
| Overall | 23% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-10 04:11:30 UTC |
| Last Seen | 2026-06-27 16:51:37 UTC |
| Profile Built | 2026-06-28 10:59:15 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 26 |
Full dossier details are available via our API.