IPDebrief

142.44.233.224

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 142.44.233.224

Classification: Moderate Risk (Score: 40/100)

Date: Intelligence compiled from current IPDebrief data

---

## Executive Summary

IP 142.44.233.224 is a cloud-based hosting infrastructure address owned by OVH (ASN 16276), operating under organization "Dmytro, Ahrefs Pte Ltd" within the 142.44.233.0/24 subnet. The address presents moderate risk due to subnet-level abuse characteristics, with 198 of 256 sibling IPs flagged as threat-related. The IP resolves to Ahrefs-hosted proxy infrastructure but exhibits no active services, indicating firewall-protected infrastructure.

---

## Technical Profile

Ownership:

Geolocation:

Network Role:

---

## Threat Indicators

Critical Finding: The subnet 142.44.233.0/24 is classified as high_abuse with an abuse density of 0.7734 (212 active siblings, 198 threat siblings). This indicates systemic abuse patterns within the subnet.

---

## Historical Observations

Signal Count: 26 observations recorded

Risk Trend: Stable moderate risk

Key historical signals include:

---

## Relationship Graph

Total Relationships: 65 entities

Primary Associations:

Implication: The IP's relationships are primarily network-level rather than indicating direct ties to specific malicious infrastructure or command-and-control entities.

---

## Neighborhood Analysis (142.44.233.0/24)

Subnet Classification: high_abuse

Abuse Density: 0.7734 (77.34%)

Sample Neighbor Risk Scores:

Context: This IP operates within a heavily abused subnet, suggesting shared infrastructure that may be leveraged for abuse by multiple actors.

---

## Recommended Actions

Firewall Blocking Recommended:

The IP presents moderate risk with subnet-level abuse context. Consider blocking in perimeter security.

Blocking Rules:

---

## Analyst Notes

1. Subnet Context: The 142.44.233.0/24 subnet shows significant abuse density. Blocking the /24 entirely may be warranted depending on operational tolerance.

2. Ahrefs Association: The DNS records (proxy-ca003-san224.ahrefs.net) indicate this IP is part of Ahrefs infrastructure. Legitimate traffic may exist; evaluate against known Ahrefs patterns before blocking.

3. No Active Services: The firewall-protected status (no open ports) reduces immediate exploitation risk but does not eliminate abuse potential.

4. Geolocation Warning: The reported geolocation shows validation failures. Do not rely on this data for geo-blocking decisions.

---

End of Briefing

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡จ๐Ÿ‡ฆ Canada
RegionQC
CityBeauharnois
Timezoneโ€”
Latitude45.51
Longitude-73.59

๐Ÿข Ownership & Registration

OrganizationDmytro, Ahrefs Pte Ltd
ASNAS16276
Network NameOVH-CUST-281059682
CIDR Block142.44.233.0/24
RIRARIN
CountrySingapore
Abuse Contactโ€”

๐ŸŒ DNS Intelligence

PTRproxy-ca003-san224.ahrefs.net
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesproxy-ca003-san224.ahrefs.net

๐Ÿ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAAPresent

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
29%
24
routing
13%
11
services
12%
22
ownership
19%
22
reputation
31%
13
geolocation
35%
23
Overall23%1015
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) โ€” 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Claimed geolocation contradicts RTT physics measurement

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-07 23:03:43 UTC
Last Seen2026-06-26 23:20:02 UTC
Profile Built2026-06-27 19:33:44 UTC
Data FreshnessLive
Signal Types25
Total Observations31
๐Ÿ” 25 signal types ยท 31 observations collected
This report is generated from 25+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.