IPDebrief

142.44.233.162

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING

Target: 142.44.233.162/32

Classification: Moderate Risk / Hosting Infrastructure

Report Generated: Current

---

## EXECUTIVE SUMMARY

IP 142.44.233.162 is a cloud-hosted infrastructure address assigned to OVH (ASN 16276) under customer allocation OVH-CUST-281059682. The IP is associated with the ahrefs.net domain and resolves to proxy-ca003-san162.ahrefs.net. Risk assessment indicates moderate risk (score: 50) with no active threat indicators. The subnet exhibits elevated abuse density, warranting defensive awareness but not immediate blocking without additional context.

---

## OWNERSHIP & INFRASTRUCTURE

AttributeValue
OrganizationDmytro, Ahrefs Pte Ltd
ASN16276 (OVH)
CIDR Block142.44.233.0/24
Infrastructure TypeCloudCompute / Hosting
Service PurposeFirewalled / No Services
Is CloudYes
Is CDNNo
Is Proxy/VPN/TorNo

Key Observation: No open ports detected. The IP is actively firewalled, indicating defensive hardening by the operator.

---

## GEOSPATIAL ANALYSIS

AttributeValue
CountryCanada (CA)
RegionQuebec (QC)
CityBeaucharnois
Claimed Coordinates45.5075°N, -73.5887°W
Geo ConfidenceLow (geo_plausible: false)

Anomaly Detected: Significant geolocation discrepancy. Probed RTT (30-37ms) is inconsistent with claimed distance of 5,597.9km from probe origin. Minimum possible RTT for that distance is 112ms. This suggests the claimed geolocation is unreliable or the IP may be misattributed.

---

## THREAT INDICATORS

IndicatorStatus
Known AttackerNo
Spam SourceNo
Tor Exit NodeNo
Blacklist Count0
Pulsedive RiskNone
Known CampaignsNone
DNSBL Listed2 of 8 lists
Operator Score0.087 (Minimal)

Assessment: No active threat indicators present. The two DNSBL listings are historical or low-severity entries requiring review.

---

## NEIGHBORHOOD ANALYSIS

Subnet: 142.44.233.162/24

MetricValue
Total Siblings256
Active Siblings212
Threat Siblings147
Abuse Density0.5742 (High)
Inherited Risk22
Risk Distribution0 High, 96 Medium, 4 Low

Observation: The /24 subnet demonstrates elevated abuse density with 147 threat-sibling IPs out of 256 total addresses. This indicates the hosting facility is commonly associated with abusive activity, though the target IP itself shows no malicious signals.

---

## OBSERVATION HISTORY

Temporal Analysis: The IP has maintained consistent ownership and infrastructure classification with no observed shifts toward malicious activity. Recent signals indicate stable, low-risk operational behavior.

---

## NETWORK RELATIONSHIPS

The IP is part of a large, consolidated customer allocation with consistent network classification.

---

## RECOMMENDED ACTIONS

PlatformAction
iptables`iptables -A INPUT -s 142.44.233.162 -j DROP`
nftables`nft add rule inet filter input ip saddr 142.44.233.162 drop`
nginx`deny 142.44.233.162;`
pfSenseBlock 142.44.233.162/32
Cloudflare WAFBlock with expression: `ip.src eq 142.44.233.162`
AWS WAFBlock address: 142.44.233.162/32

Recommendation Level: Moderate

Rationale: While the IP shows no active threat indicators, the subnet's high abuse density (0.5742) and presence on 2 DNSBL lists warrant defensive blocking. The firewall-hardened state suggests the IP may be used for non-interactive purposes or as part of compromised infrastructure.

---

## ANALYST NOTES

1. Subnet Context: The 142.44.233.0/24 subnet is classified as "high_abuse" with 57.42% abuse density. Monitor other IPs in the block for correlation.

2. Ahrefs Association: Domain resolution to ahrefs.net indicates potential legitimate SEO tooling usage, though this cannot be verified without additional context.

3. Geolocation Caution: Do not rely on the claimed Beaucharnois, QC location due to RTT validation failure.

4. Operational Status: No open services detected. This may indicate legitimate server hardening or abuse mitigation.

---

END OF BRIEFING

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡จ๐Ÿ‡ฆ Canada
RegionQC
CityBeauharnois
Timezoneโ€”
Latitude45.51
Longitude-73.59

๐Ÿข Ownership & Registration

OrganizationDmytro, Ahrefs Pte Ltd
ASNAS16276
Network NameOVH-CUST-281059682
CIDR Block142.44.233.0/24
RIRARIN
CountrySingapore
Abuse Contactโ€”

๐ŸŒ DNS Intelligence

PTRproxy-ca003-san162.ahrefs.net
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesproxy-ca003-san162.ahrefs.net

๐Ÿ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAAPresent

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
30%
24
routing
13%
11
services
17%
23
ownership
19%
22
reputation
28%
13
geolocation
35%
23
Overall24%1016
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) โ€” 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Claimed geolocation contradicts RTT physics measurement

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-08 17:17:37 UTC
Last Seen2026-06-27 13:31:55 UTC
Profile Built2026-06-28 07:36:15 UTC
Data FreshnessLive
Signal Types24
Total Observations31
๐Ÿ” 24 signal types ยท 31 observations collected
This report is generated from 24+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.