# IP Intelligence Briefing: 148.113.128.247/32
Classification: Moderate Risk | Provider: OVH | Date: 2026-06-25
---
## Executive Summary
IP address 148.113.128.247 is registered to Ahrefs Pte Ltd under OVH Cloud infrastructure (ASN 16276). The IP shows moderate risk (score: 50) with evidence of hosting infrastructure activity and geolocation inconsistencies. The subnet exhibits high abuse density (0.543), with 139 threat-sibling IPs identified within the /24 block.
---
## Technical Profile
Ownership & Classification:
- Organization: Ahrefs Pte Ltd (Dmytro)
- Network: 148.113.128.0/24
- ASN: 16276 (OVH SAS)
- Infrastructure Type: Cloud hosting
- Service Status: Firewalled / No services detected
Geolocation:
- Reported: Singapore (city), CA (country)
- Validation: FAILED โ GeoPlausible flag false
- RTT Anomaly: 28ms observed vs 121.6ms minimum for 6082km distance
- Accuracy radius: 3000km
DNS Resolution:
- PTR: proxy-ca014-san247.ahrefs.net
- Domain: ahrefs.net
- Forward resolution: Confirmed
- Email authentication: No SPF/DMARC records
---
## Threat Indicators
Current Status:
- Risk Score: 50/100 (Moderate)
- Blacklist Count: 0
- Tor Exit: No
- Known Attacker: No
- Spam Source: No
- Campaigns: None detected
DNSBL Reputation:
- Listed on 2 of 8 DNSBLs
- DNSBL Listed Count: 2 (Control Plane)
Neighborhood Analysis:
- Subnet Abuse Density: 0.543 (high_abuse classification)
- Total Siblings: 256
- Active Siblings: 200
- Threat Siblings: 139
- Risk Distribution: 100 medium-risk IPs, 0 high/low
---
## Historical Observations (22 signals)
Recent Activity:
- 2026-06-25: Cloud infrastructure confirmed (OVH), hosting flags active
- 2026-06-24: Multiple DNSBL listings detected (high severity)
- 2026-06-25: Threat signals observed via AlienVault OTX
Temporal Indicators:
- Ownership changes: 0
- Threat persistence days: 0
- Observation count: 1 threat signal
- Not persistently malicious
---
## Recommended Actions
Firewall/Blocking Rules:
- iptables: `iptables -A INPUT -s 148.113.128.247 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 148.113.128.247 drop`
- nginx: `deny 148.113.128.247;`
- pfSense: `148.113.128.247/32`
- Cloudflare WAF: Block with expression `ip.src eq 148.113.128.247`
- AWS WAF: Address `148.113.128.247/32`
Assessment Note: Recommendations are probabilistic; combine with additional signals before enforcement.
---
## SOC Analyst Notes
1. Subnet Correlation: 139 threat-sibling IPs in the same /24 block warrant expanded monitoring of related addresses.
2. Geolocation Discrepancy: RTT and country/city mismatch suggests potential spoofing or proxy use. Investigate if legitimate Ahrefs traffic patterns match this profile.
3. Infrastructure Context: Hosting classification with no open services indicates this IP is not directly accessible; threat activity may originate from or target this address.
4. DNSBL Presence: Two DNSBL listings indicate prior abuse or spam association, though current blacklist count shows zero.
Priority: Medium โ Monitor subnet activity and correlate with known Ahrefs traffic baselines.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059693 |
| CIDR Block | 148.113.128.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca014-san247.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca014-san247.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 23% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-09 22:10:45 UTC |
| Last Seen | 2026-06-27 16:35:11 UTC |
| Profile Built | 2026-06-28 10:41:51 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 25 |
Full dossier details are available via our API.