# IP INTELLIGENCE BRIEFING
Target: 142.44.233.131/32
Analysis Date: 2026-06-17
Classification: Moderate Risk (Context-Dependent)
---
## EXECUTIVE SUMMARY
IP 142.44.233.131 presents a contextually elevated risk profile despite its individual risk score of 30 (Low Risk). The address operates within a high-abuse subnet (142.44.233.0/24) with an abuse density of 0.75 and 192 threat siblings out of 206 active addresses. While the IP resolves to a legitimate domain (ahrefs.net), the subnet-level indicators suggest compromised infrastructure sharing.
---
## PROFILE ANALYSIS
| Attribute | Value |
|---|---|
| **Risk Score** | 30 (Low) |
| **ASN** | 16276 (OVH) |
| **Organization** | Dmytro, Ahrefs Pte Ltd |
| **Network** | 142.44.233.0/24 |
| **Infrastructure** | CloudCompute / Hosting |
| **DNS Record** | proxy-ca003-san131.ahrefs.net |
| **Open Ports** | None detected |
| **Geolocation** | CA (Inconsistent) |
Key Indicator: The IP's DNS record resolves to ahrefs.net, a legitimate SEO tools provider. However, geolocation data shows inconsistencies (Country: CA with implausible coordinates 56.13°N, -106.35°W), suggesting potential DNS hijacking or misconfiguration.
---
## SUBNET THREAT CONTEXT
The parent subnet demonstrates concerning abuse patterns:
- Abuse Density: 0.75 (High)
- Classification: high_abuse
- Total Siblings: 256
- Active Siblings: 206
- Threat Siblings: 192 (93% of active addresses)
- Risk Distribution: 0 High, 94 Medium, 6 Low
Assessment: This subnet shows near-uniform abuse characteristics. The high threat sibling count indicates systematic infrastructure compromise, likely due to shared hosting infrastructure or botnet propagation within the /24 block.
---
## OBSERVATION HISTORY
27 historical observations tracked since initial discovery:
- Most Recent (2026-06-17): Confirmed high_abuse classification with 0.75 abuse density
- Routing Signals: Moderate operator score (0.6522), valid RPKI state, stable BGP routing
- DNS Consistency: ahrefs.net domain observed consistently
- Persistence: Threat observation count: 1; Not persistently malicious
---
## RELATIONSHIP MAPPING
44 detected relationships identified, primarily:
- Multiple Same Network relationships to OVH-CUST-281059682
- Control plane origin: ASN 16276
No certificate subjects or campaign correlations detected.
---
## SECURITY RECOMMENDATIONS
Immediate Actions:
1. Monitor but do not block at this time. The IP shows no active threat indicators (no blacklist listings, no known campaigns).
2. Apply subnet-level scrutiny given the 93% threat sibling ratio. Consider blocking the entire /24 if security posture permits.
3. Validate DNS resolution - the geolocation inconsistency warrants verification.
Firewall Rules: No specific rules generated due to low individual risk score. Monitor for behavioral anomalies.
---
## CONCLUSION
The target IP presents moderate contextual risk. While the individual address shows no malicious indicators, the high-abuse subnet environment suggests potential for infrastructure sharing with compromised hosts. SOC teams should maintain elevated monitoring for traffic patterns from this subnet rather than immediate blocking, which could impact legitimate ahrefs.net traffic.
Priority: Medium
Recommended Action: Enhanced monitoring with subnet-level awareness
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059682 |
| CIDR Block | 142.44.233.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca003-san131.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca003-san131.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 2 โ Moderate operator sophistication with routing hygiene |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 22% | 3 | 4 |
| services | 12% | 2 | 2 |
| ownership | 26% | 3 | 3 |
| reputation | 30% | 1 | 3 |
| geolocation | 34% | 2 | 3 |
| Overall | 26% | 13 | 19 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:43 UTC |
| Last Seen | 2026-06-26 23:15:41 UTC |
| Profile Built | 2026-06-27 19:29:01 UTC |
| Data Freshness | Live |
| Signal Types | 27 |
| Total Observations | 35 |
Full dossier details are available via our API.