# IP INTELLIGENCE BRIEFING
Target: 142.44.233.152/32
Date: 2026-06-15
Classification: Moderate Risk
## EXECUTIVE SUMMARY
IP 142.44.233.152 is a moderate-risk address (score: 40) associated with OVH hosting infrastructure. The IP resolves to a proxy hostname for ahrefs.net but operates with firewalled/no service configuration. Subnet abuse density is elevated at 0.6914 with high_abuse classification. No active port services detected; DNSBL listed on 1 of 8 threat feeds.
## OWNERSHIP & NETWORK CLASSIFICATION
- Organization: Dmytro, Ahrefs Pte Ltd (OVH customer)
- ASN: 16276 (OVH)
- CIDR Block: 142.44.233.0/24
- Network Role: Hosting Provider (OVH)
- Geolocation: Canada (QC) per registration; geolocation validation shows 5,598km distance from expected origin with RTT violation indicating data inconsistency
## THREAT INDICATORS
- Risk Score: 40 (Moderate)
- Abuse Confidence Score: Not available
- Blacklist Count: 1 (of 8 total lists)
- Tor Exit Node: False
- Known Attacker: False
- Spam Source: False
- DNSBL Listed: Yes (1 of 8 lists)
- Operator Score: 0.2174 (Minimal)
- Stability Score: 0 (Low)
## NETWORK BEHAVIOR
- Open Ports: None detected
- HTTP Services: None detected
- TLS Certificate: None detected
- DNS Resolution: proxy-ca003-san152.ahrefs.net (1 forward resolution)
- PTR Hostname: proxy-ca003-san152.ahrefs.net
- Service Status: Firewalled / No Services
## SUBNET ENVIRONMENT ANALYSIS
Subnet: 142.44.233.0/24
Abuse Density: 0.6914 (High Abuse)
Total Siblings: 256
Active Siblings: 198
Threat Siblings: 177
Neighbor Risk Distribution: 0 high, 94 medium, 6 low
The /24 subnet exhibits elevated threat activity with 89% of active siblings classified as threats. Inherited risk score: 27.
## OBSERVATION HISTORY
- Total Observations: 19
- Most Recent: 2026-06-15 13:10:09 UTC
- Threat Persistence: 0 days (not persistently malicious)
- Ownership Changes: 0
- Recent Signals:
- Abuse density maintained at 0.6914 (high_abuse)
- Operator score: 0.2174 (minimal)
- CAA records present with 1 issuer
- DNSSEC: Valid
## RELATIONSHIP GRAPH
- Same Network Relationships: 40 entries (all pointing to OVH-CUST-281059682)
- Correlated Entities: None identified beyond network-level associations
## RECOMMENDED ACTIONS
Based on risk profile and subnet context:
1. Monitor Closely: Moderate risk score combined with high-abuse subnet warrants enhanced monitoring
2. DNSBL Verification: Investigate which of the 8 DNSBLs lists this IP
3. Traffic Analysis: Review connection logs for any outbound connections to this IP or related ahrefs.net domains
4. Subnet Context: Consider subnet-level reputation when evaluating traffic from 142.44.233.0/24
## INTELLIGENCE NOTES
This IP appears to be part of OVH hosting infrastructure associated with Ahrefs proxy services. While no active services are detected, the subnet's elevated abuse density (0.6914) suggests this infrastructure may be used for legitimate purposes alongside potential abuse. The geolocation data inconsistency (CA country code with Singapore city field) warrants further investigation for potential spoofing or misconfiguration.
---
Analyst: IPDebrief Intelligence System
Data Sources: IPDebrief Platform v2026
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059682 |
| CIDR Block | 142.44.233.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca003-san152.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca003-san152.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 23% | 9 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-21 20:59:14 UTC |
| Last Seen | 2026-06-28 15:10:32 UTC |
| Profile Built | 2026-06-29 09:16:16 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 23 |
Full dossier details are available via our API.