THREAT INTELLIGENCE BRIEFING
Target IP: 148.113.128.204/32
Date: Intelligence assessment compiled from current data
Classification: Moderate Risk (Score: 40)
---
OWNERSHIP & INFRASTRUCTURE
The IP address belongs to ASN 16276 (OVH), registered under "Dmytro, Ahrefs Pte Ltd" (OVH-CUST-281059693). The address is allocated within the 148.113.128.0/24 block and operates as cloud compute infrastructure with firewalled/no services configuration. The infrastructure is hosted through OVH's cloud platform.
DNS & NETWORK CHARACTERISTICS
Reverse DNS resolves to "proxy-ca014-san204.ahrefs.net" with forward confirmation to the same hostname. No open ports detected on the target. DNSSEC validation is valid, and CAA records are present. The IP is listed on 1 DNSBL out of 8 total checks.
GEOLOCATION ANALYSIS
IP geolocation data indicates Canada (CA), however geolocation validation flags a significant discrepancy: the IP's observed RTT (27ms average) contradicts the reported location, which would require minimum 121.6ms RTT for 6082km distance. This suggests potential geolocation spoofing or data inconsistency requiring additional verification.
THREAT ASSESSMENT
- Risk Score: 40 (Moderate)
- Abuse Confidence: Not scored
- Known Attack Source: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Status: 0 known blacklists (IPDebrief data)
- Campaign Affiliation: None identified
SUBNET CONTEXT
The /24 subnet (148.113.128.0/24) exhibits high abuse density (0.6016). Of 256 total sibling IPs, 204 are active with 154 classified as threat siblings, indicating the subnet is heavily utilized. The target IP inherits risk score of 24 from subnet context.
OBSERVATION HISTORY
22 signal observations recorded. Recent activity (2026-06-15 through 2026-06-20) shows consistent DNS resolution to ahrefs.net domain with stable operator score (0.2174). No evidence of escalating threat behavior over the observation window.
RELATIONSHIP GRAPH
34 relationships identified, predominantly network-level associations within OVH-CUST-281059693. No external organization, hostname, or certificate relationships detected beyond the ahrefs.net domain.
RECOMMENDED ACTIONS
The IP presents moderate risk due to high-abuse subnet context and geolocation inconsistencies. Recommended countermeasures include:
Firewall Rules:
- iptables: `iptables -A INPUT -s 148.113.128.204 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 148.113.128.204 drop`
- nginx: `deny 148.113.128.204;`
- pfSense: `148.113.128.204/32`
- Cloudflare WAF: Block with expression `ip.src eq 148.113.128.204`
- AWS WAF: Add `148.113.128.204/32` to block list
SOC Analyst Notes:
- Monitor for service initiation (currently no open ports)
- Investigate geolocation discrepancy as potential indicator of misconfiguration or malicious activity
- Consider blocking at perimeter due to high-abuse subnet density
- Review for correlation with other ahrefs.net infrastructure
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059693 |
| CIDR Block | 148.113.128.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca014-san204.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca014-san204.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 34% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 23% | 1 | 2 |
| geolocation | 33% | 2 | 3 |
| Overall | 22% | 10 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-23 18:28:38 UTC |
| Last Seen | 2026-06-28 22:22:55 UTC |
| Profile Built | 2026-06-29 04:25:56 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 23 |
Full dossier details are available via our API.