IP INTELLIGENCE BRIEFING: 148.113.128.175/32
Target Overview:
- IP Address: 148.113.128.175
- Risk Score: 40 (Moderate Risk)
- Infrastructure Provider: OVH (ASN 16276)
- Organization: Dmytro, Ahrefs Pte Ltd
- Network Block: 148.113.128.0/24
- Classification: Cloud Compute / Hosting Environment
Geolocation Discrepancy:
Geolocation data indicates Canada (CA) with Singapore city designation. RTT validation shows significant inconsistency: observed RTT of 28ms vs minimum possible 121.6ms for the claimed 6,082km distance. This geographic mismatch warrants further investigation.
DNS Resolution:
- PTR Hostname: proxy-ca014-san175.ahrefs.net
- Forward Resolution: proxy-ca014-san175.ahrefs.net
- Domain: ahrefs.net
- Forward confirmation failed (forwardConfirmed: false)
Network Services:
- No open ports detected
- Infrastructure type: Cloud Compute
- Service status: Firewalled / No Services
- TLS/HTTP: No active web services observed
Threat Indicators:
- Abuse Confidence Score: Not applicable
- Blacklist Count: 0
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- DNSBL Listed: 1 of 8 lists
- Known Campaigns: None identified
Neighborhood Analysis (148.113.128.0/24):
- Subnet classification: High abuse
- Abuse density: 0.6055
- Total siblings: 256
- Active siblings: 204
- Threat siblings: 155 (61% of active)
- Inherited risk score: 24
- All neighbor IPs show consistent risk score of 40 (medium)
Control Plane Data:
- Origin ASN: 16276
- BGP Prefix: 148.113.128.0/17
- Route stability: Unstable
- RPKI State: Not validated
- DNSSEC: Valid
- Operator score: 0.2174 (Minimal)
Observation History:
- Multiple signals observed from June 2026
- Geo validation violations consistently recorded
- Abuse density classification maintained at high levels
- No persistent malicious activity detected
- Campaign correlation: None
Related Entities:
- 34 relationships identified, all mapped to same network block (OVH-CUST-281059693)
- No certificate relationships detected
- No correlated IPs in campaigns
Recommended Actions:
1. Monitor for service activation (currently firewalled)
2. Validate geographic discrepancy through additional triangulation
3. Block if abuse indicators emerge (currently moderate risk)
4. Review for potential Ahrefs-related infrastructure activity
Assessment:
This IP represents a moderately risky cloud hosting environment under OVH infrastructure with ahrefs.net DNS association. The subnet exhibits elevated abuse density with 155 of 204 active siblings flagged as threats. Geographic inconsistencies and route instability suggest infrastructure that may be repurposed for malicious activities. Current lack of open services reduces immediate threat, but monitoring is recommended for service activation patterns.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059693 |
| CIDR Block | 148.113.128.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca014-san175.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca014-san175.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 23% | 1 | 2 |
| geolocation | 34% | 2 | 3 |
| Overall | 23% | 10 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-23 12:22:01 UTC |
| Last Seen | 2026-06-28 21:02:15 UTC |
| Profile Built | 2026-06-29 03:04:50 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 23 |
Full dossier details are available via our API.