# IP Intelligence Briefing: 142.44.233.52/32
Classification: Moderate Risk
Date Generated: 2026-06-20
Analyst: IPDebrief Intelligence Team
---
## Executive Summary
IP 142.44.233.52 is a cloud-based infrastructure asset hosted on OVH (ASN 16276) with a moderate risk score of 40. The IP resolves to the ahrefs.net domain (proxy-ca003-san52.ahrefs.net) and operates within an OVH customer block (OVH-CUST-281059682). Current observation shows the IP is firewalled with no open services detected.
---
## Technical Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 40 (Moderate Risk) |
| **Provider** | OVH (ASN 16276) |
| **Organization** | Dmytro, Ahrefs Pte Ltd |
| **Network Block** | 142.44.233.0/24 |
| **Infrastructure Type** | Cloud Compute / Hosting |
| **Geolocation Claim** | Canada (QC) |
| **Geolocation Discrepancy** | RTT indicates Singapore (~5,598 km) |
---
## Threat Assessment
Active Indicators
- DNSBL Status: Listed on 1 of 8 DNS blacklists
- DNSBL Severity: High
- Operator Score: 0.2174 (Minimal)
- Route Stability: Unstable (route_changes_30d: 0, isRouteStable: false)
Negative Signals
- Geo-validation failure: Claimed location (Canada) inconsistent with RTT measurements indicating Singapore
- No forward DNS resolution confirmation
- No email authentication records (SPF/DMARC)
Positive Signals
- No Tor/VPN/proxy indicators
- No known attacker or spam source flags
- No active threat campaigns correlated
- Domain (ahrefs.net) has valid CAA records
---
## Neighborhood Analysis
Subnet: 142.44.233.0/24
Abuse Density: 0.6914 (High Abuse Classification)
The /24 subnet contains 256 sibling addresses with 198 currently active. Threat analysis reveals:
- 177 threat-identified siblings
- 96 medium-risk neighbors
- 4 low-risk neighbors
- 0 high-risk neighbors
This indicates the subnet is heavily utilized, with approximately 70% of active IPs flagged as threats. Context suggests this is a shared hosting environment.
---
## Historical Context
18 total observations recorded. Recent activity shows:
- Persistent cloud/hosting classification
- DNS blacklist activity detected
- Geolocation inconsistencies consistent across probes
No persistent malicious behavior patterns identified (threatPersistenceDays: 0).
---
## Related Entities
41 relationship records identified, primarily Same Network associations with OVH-CUST-281059682. No certificate-based or hostname-based relationships beyond the ahrefs.net domain.
---
## Recommended Actions
Priority: Monitor/Block
```bash
# iptables
iptables -A INPUT -s 142.44.233.52 -j DROP
# nftables
nft add rule inet filter input ip saddr 142.44.233.52 drop
# pfSense
142.44.233.52/32
# Cloudflare WAF
{"description":"Block 142.44.233.52 โ IPDebrief risk score 40","action":"block","filter":{"expression":"ip.src eq 142.44.233.52"}}
# AWS WAF
{"Addresses":["142.44.233.52/32"],"Description":"IPDebrief risk 40"}
```
---
## Intelligence Conclusion
The IP represents a legitimate cloud infrastructure asset (ahrefs.net proxy endpoint) operating in a high-abuse-density subnet. While the IP itself shows moderate risk and no active threat indicators, the subnet environment warrants defensive attention. The geo-location discrepancy and DNSBL listing suggest potential misconfiguration or shared IP abuse.
Recommended: Implement blocking rules with awareness that this may impact legitimate ahrefs.net service. Monitor for service disruption and consider whitelist evaluation if business operations require ahrefs.net connectivity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059682 |
| CIDR Block | 142.44.233.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca003-san52.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca003-san52.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 23% | 9 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-21 20:59:15 UTC |
| Last Seen | 2026-06-28 15:13:42 UTC |
| Profile Built | 2026-06-29 03:17:13 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 21 |
Full dossier details are available via our API.