IP Intelligence Briefing: 142.44.233.86
Date: 2026-06-16
Key Findings:
1. Risk Profile:
- Moderate Risk (Score: 50) with no direct malicious indicators.
- Network Classification: CloudCompute infrastructure (OVH-hosted), likely a firewalled server.
- Geolocation: Conflicting dataβregistered to Canada (CA) but linked to Singapore via DNS (proxy-ca003-san86.ahrefs.net).
2. Ownership & Subnet:
- Registered to Ahrefs Pte Ltd (OVH ASN 16276).
- Subnet 142.44.233.0/24 has high abuse density (0.5938), with 152/256 IPs flagged as threats.
- 185 active siblings in the subnet, 152 with threat indicators.
3. Threat & Behavioral Data:
- No detected spam, attacker, or Tor exit node activity.
- Subnet shows high abuse classification, but the IP itself has no direct malicious signals.
4. DNS & Relationships:
- Linked to proxy-ca003-san86.ahrefs.net (DNS PTR hostname).
- No email authentication records (SPF/DKIM).
- Strong DNSSEC and CAA records, but listed on 2/8 DNSBLs.
5. Network Neighbors:
- Subnet contains 92 medium-risk IPs and 8 low-risk IPs.
- Abuse density suggests potential for lateral movement or compromised neighbors.
Recommended Actions:
- Monitor the 142.44.233.0/24 subnet for unusual traffic patterns due to high abuse density.
- Validate geolocation anomalies (Canada vs. Singapore) with additional probing.
- Investigate DNSBL listings for potential reputation risks.
- Consider rate-limiting or blocking traffic from high-risk neighbors if the IP is a critical asset.
Conclusion:
This IP appears to be a legitimate cloud server operated by Ahrefs, but its subnetβs high abuse density warrants closer scrutiny. No immediate threat to the IP itself, but network-wide risks may exist. SOC teams should prioritize monitoring the subnet and verifying geolocation inconsistencies.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059682 |
| CIDR Block | 142.44.233.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca003-san86.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca003-san86.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 19% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 13% | 1 | 2 |
| geolocation | 15% | 2 | 2 |
| Overall | 16% | 10 | 11 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-29 18:14:13 UTC |
| Last Seen | 2026-06-29 06:35:00 UTC |
| Profile Built | 2026-06-29 06:43:50 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 19 |
Full dossier details are available via our API.