IP INTELLIGENCE BRIEFING
Target: 148.113.128.100/32
Date: 2026-06-28
Classification: Moderate Risk (Score: 40)
---
EXECUTIVE SUMMARY
IP 148.113.128.100 is a cloud-hosting address (OVH) operating within a high-abuse-density subnet (148.113.128.0/24). The IP resolves to Ahrefs proxy infrastructure (proxy-ca014-san100.ahrefs.net) but exhibits geographic inconsistencies and moderate threat indicators. No active services detected on port scan.
---
INFRASTRUCTURE ANALYSIS
Network Assignment:
- ASN: 16276 (OVH SAS)
- Organization: Dmytro, Ahrefs Pte Ltd
- CIDR Block: 148.113.128.0/24
- Network Role: Hosting provider (firewalled/no services)
Geolocation Discrepancy:
- Reported Country: Canada (CA)
- Reported City: Singapore
- Validation Failure: RTT analysis indicates 6,082 km distance from probe location with 25ms RTT, which is physically impossible (minimum possible RTT: 121.6ms). Geographic data marked as implausible.
DNS Resolution:
- PTR Record: proxy-ca014-san100.ahrefs.net
- Forward Resolution: Confirmed to ahrefs.net
- Email Authentication: No SPF/DMARC records configured
---
THREAT INDICATORS
Current Status:
- Risk Score: 40 (Moderate)
- Blacklist Status: Not currently listed (0 blacklists)
- Campaign Activity: No known campaigns associated
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
Control Plane Anomalies:
- Route stability: Unstable (isRouteStable: false)
- DNSBL Listings: 1 out of 8 total lists
- Operator Score: 0.2174 (Minimal)
- Threat Observation Count: 1
---
SUBNET CONTEXT (148.113.128.0/24)
Abuse Profile:
- Abuse Density: 0.5898 (High abuse classification)
- Active Siblings: 204 of 256 total IPs
- Threat Siblings: 151 IPs flagged as threats
- Neighbor Risk Distribution: 100 medium-risk, 0 high-risk, 0 low-risk
Neighborhood Risk: All sibling IPs in the /24 subnet show consistent risk scoring of 40, indicating systematic risk patterns across this hosting block.
---
OBSERVATION HISTORY (19 signals)
Recent observations reveal:
- Cloud Infrastructure: Confirmed OVH cloud compute environment
- Infrastructure Type: CloudCompute
- No Persistent Threats: Threat persistence days: 0
- Ownership Stability: No ownership changes detected
---
RECOMMENDED ACTIONS
Immediate Mitigation:
The system recommends blocking this IP address across perimeter security controls due to moderate risk classification and high-abuse neighborhood context.
Firewall Rules (Ready for Deployment):
```bash
# iptables
iptables -A INPUT -s 148.113.128.100 -j DROP
# nftables
nft add rule inet filter input ip saddr 148.113.128.100 drop
# Cloudflare WAF
Filter: ip.src eq 148.113.128.100 โ Block
# AWS WAF
Addresses: 148.113.128.100/32 โ Block
```
SOC Analyst Guidance:
1. Block traffic from 148.113.128.100/32 at perimeter firewalls
2. Consider blocking the broader /24 subnet (148.113.128.0/24) given high abuse density (151 threat siblings)
3. Monitor for lateral activity from this subnet if previously trusted
4. Ahrefs infrastructure usage may indicate legitimate marketing tools or potential credential stuffing operations
5. Verify if any observed traffic correlates with known Ahrefs service patterns
---
END OF BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059693 |
| CIDR Block | 148.113.128.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca014-san100.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca014-san100.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 15% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 22% | 9 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-21 20:59:17 UTC |
| Last Seen | 2026-06-28 15:14:54 UTC |
| Profile Built | 2026-06-29 09:20:57 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 22 |
Full dossier details are available via our API.