# IP Intelligence Briefing: 142.44.233.251/32
## Executive Summary
IP address 142.44.233.251 was analyzed as a moderate-risk (50/100) cloud infrastructure endpoint operated by OVH Holdings under ASN 16276. The IP resolved to ahosted domain (ahrefs.net) but exhibited geolocation inconsistencies and operated within a high-abuse-density subnet. No active threat indicators were detected, but the IP should be monitored for potential abuse activity.
## Technical Profile
Risk Assessment: 50/100 (Moderate Risk)
Network Classification: Cloud Compute / Hosting
Infrastructure Provider: OVH (ASN: 16276)
CIDR Block: 142.44.233.0/24
Geolocation: Canada (CA) / Singapore (QC) โ *Data inconsistency detected*
DNS Resolution:
- PTR Record: proxy-ca003-san251.ahrefs.net
- Forward Resolution: ahrefs.net
- Hosted Domain: ahrefs.net
## Threat Indicators
- Known Attacker Status: False
- Spam Source Status: False
- Tor Exit Node: False
- Blacklist Status: 0 direct listings
- DNSBL Listings: 2/8 total lists (dnsblListedCount)
- Known Campaigns: None identified
- Threat Feeds: No active threat feed matches
Control Plane Data:
- BGP Prefix: 142.44.128.0/17
- Route Stability: False
- DNSSEC Valid: True
- Operator Score: 0.2174 (Minimal)
- DNSBL Listed Count: 2
## Neighborhood Analysis
Subnet: 142.44.233.0/24
- Abuse Density: 0.6992 (High Abuse Classification)
- Total Subnet Siblings: 256
- Active Siblings: 198
- Threat Siblings: 179
- Inherited Risk Score: 27
The subnet shows elevated abuse activity with 69.92% abuse density. Of 198 active sibling IPs, 179 (89.4%) were identified as threat sources.
## Historical Observations (21 Total)
Signal history indicates temporal activity with notable events on 2026-06-18 and 2026-06-20:
- 2026-06-18: Operator score signal (confidence: 0.85) with maximum severity: high; DNS records verified for ahrefs.net
- 2026-06-20: Operator score observations with minimal operator scores (0.2174)
- Subnet Abuse Density: Consistently classified as high_abuse (0.6992) across multiple observations
No persistent malicious behavior detected (threatPersistenceDays: 0).
## Network Relationships
38 relationships identified, all classified as "Same Network" type pointing to OVH-CUST-281059682. No relationships detected to external organizations, hostnames, or certificates outside the OVH infrastructure.
## Network Services
- Open Ports: None detected (service classification: Firewalled / No Services)
- TLS Certificate: Not detected
- HTTP Service: Not detected
- Mobile/Residential: False
## Recommended Security Actions
Based on risk profile, the following firewall rules are recommended:
General Blocking Rules:
```bash
# iptables
iptables -A INPUT -s 142.44.233.251 -j DROP
# nftables
nft add rule inet filter input ip saddr 142.44.233.251 drop
# nginx
deny 142.44.233.251;
```
Cloud/WAF Rules:
- pfSense: 142.44.233.251/32
- Cloudflare WAF: Block IP (expression: ip.src eq 142.44.233.251)
- AWS WAF: 142.44.233.251/32
## Intelligence Assessment
The IP address operates within OVH cloud infrastructure with a legitimate hosting association (ahrefs.net). While no active threat indicators were identified, the subnet-level abuse density (0.6992) and high number of threat siblings (179/198 active IPs) suggest elevated risk. The IP is recommended for monitoring and consideration for blocking, particularly given the geolocation inconsistencies and subnet abuse context.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059682 |
| CIDR Block | 142.44.233.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca003-san251.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca003-san251.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 25% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-23 12:21:57 UTC |
| Last Seen | 2026-06-28 20:59:44 UTC |
| Profile Built | 2026-06-29 15:06:12 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 25 |
Full dossier details are available via our API.