IPDebrief

148.113.128.20

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING

Target: 148.113.128.20/32

Risk Assessment: Moderate Risk (Score: 40/100)

Analysis Date: [Current Date]

---

## EXECUTIVE SUMMARY

IP address 148.113.128.20 is assigned to OVH SAS (ASN 16276) and registered to Dmytro, Ahrefs Pte Ltd under network block 148.113.128.0/24. The IP resolves to proxy-ca014-san20.ahrefs.net and is classified as cloud hosting infrastructure. While currently showing no active threat indicators, the IP resides within a high-abuse-density subnet (0.5898) with 151 of 256 sibling IPs flagged as threats.

---

## OWNERSHIP & INFRASTRUCTURE

AttributeValue
ASN16276
OrganizationDmytro, Ahrefs Pte Ltd
ProviderOVH SAS
Network Block148.113.128.0/24
LocationCanada (QC, Beauharnois)
Infrastructure TypeCloudCompute
ClassificationCloud Hosting

Geolocation Validation: Geovalidation flags indicate inconsistencyβ€”reported location (Beauharnois, QC) shows RTT violation (29ms observed vs. 121.6ms minimum required for 6,082km distance). Multiple geolocation sources provide conflicting data with consensus not achieved.

---

## THREAT POSTURE

Current Status: No active threat indicators detected

DNS Configuration:

---

## OBSERVATION HISTORY

Analysis of 21 historical observations reveals temporal volatility:

---

## NEIGHBORHOOD ANALYSIS

Subnet: 148.113.128.0/24

Abuse Density: 0.5898 (High)

Inherited Risk: 23/100

MetricValue
Total Siblings256
Active Siblings204
Threat Siblings151
Risk DistributionMedium: 100 / Low: 0 / High: 0

The subnet shows elevated abuse activity, with approximately 59% of IPs flagged as threats. This context warrants heightened monitoring despite the target IP's current clean status.

---

## NETWORK RELATIONSHIPS

35 relationships identified, primarily:

---

## SECURITY RECOMMENDATIONS

Risk Score: 40/100 (Moderate)

Recommendation: Monitor with optional blocking based on operational requirements

Recommended Firewall Rules:

```

iptables: iptables -A INPUT -s 148.113.128.20 -j DROP

nftables: nft add rule inet filter input ip saddr 148.113.128.20 drop

nginx: deny 148.113.128.20;

```

Cloud Platform Rules:

---

## ANALYST NOTES

1. Subnet Context: The high abuse density in 148.113.128.0/24 (151 threat siblings) suggests this IP block is frequently abused. Blocking may reduce lateral movement risk.

2. Ahrefs Association: DNS resolution to ahrefs.net indicates legitimate use case, but the hosting provider (OVH) is known for high-abuse density.

3. Temporal Signals: Historical data shows transient threat listings, suggesting the IP has been reused or reassigned previously.

4. Action Threshold: At Risk Score 40, this IP falls in the moderate-risk category. Blocking is recommended if the organization has strict threat posture requirements.

5. Monitoring Priority: Mediumβ€”maintain logging and monitor for service activity or reputation changes.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡¨πŸ‡¦ Canada
RegionQC
CityBeauharnois
Timezoneβ€”
Latitude43.63
Longitude-79.37

🏒 Ownership & Registration

OrganizationDmytro, Ahrefs Pte Ltd
ASNAS16276
Network NameOVH-CUST-281059693
CIDR Block148.113.128.0/24
RIRARIN
CountrySingapore
Abuse Contactβ€”

🌐 DNS Intelligence

PTRproxy-ca014-san20.ahrefs.net
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesproxy-ca014-san20.ahrefs.net

πŸ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAAPresent

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting β€” Infrastructure provider without advanced routing
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
39%
23
routing
13%
11
services
8%
11
ownership
19%
22
reputation
31%
13
geolocation
39%
23
Overall25%913
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) β€” 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Claimed geolocation contradicts RTT physics measurement

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-21 20:59:17 UTC
Last Seen2026-06-28 15:17:18 UTC
Profile Built2026-06-29 03:21:45 UTC
Data FreshnessLive
Signal Types20
Total Observations22
πŸ” 20 signal types Β· 22 observations collected
This report is generated from 20+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.