# IP Intelligence Briefing: 148.113.128.65
## Executive Summary
IP address 148.113.128.65 operates within OVH infrastructure under assignment to Dmytro, Ahrefs Pte Ltd. The IP presents moderate risk (score: 40/100) and is associated with high-abuse density hosting environment. No active threat indicators or service exposure detected. Recommended defensive posture: monitor or block based on operational context.
## Risk Assessment
| Metric | Value |
|---|---|
| Risk Score | 40 (Moderate Risk) |
| Provider Score | 0 |
| Authority Score | 0 |
| Stability Score | 0 |
| Abuse Confidence | Not Reported |
| Blacklist Count | 0 |
## Network Classification
- Provider: OVH (ASN 16276)
- Infrastructure Type: Cloud Compute
- Service Purpose: Firewalled / No Services
- CIDR Block: 148.113.128.0/24
- DNS PTR: proxy-ca014-san65.ahrefs.net
- Hosted Domain: ahrefs.net
## Geographic Validation
- Claimed Location: Singapore
- Validation Status: Implausible
- Geographic Distance: 6,082 km from probe location
- RTT Violation: 28.0ms measured vs 121.6ms minimum possible
- Probe Count: 5
- Conclusion: Geolocation data unreliable; actual origin unknown
## Neighborhood Analysis
The /24 subnet exhibits high abuse characteristics:
- Abuse Density: 0.668 (High)
- Total Siblings: 256
- Active Siblings: 208
- Threat Siblings: 171
- Inherited Risk: 26
- Risk Distribution: 100 medium-risk neighbors, 0 high/low risk
## Threat Indicators
- Threat Indicators: None detected
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Campaign Likelihood: None
- DNSBL Listings: 1 of 8 lists
## Control Plane
- Route Stability: Unstable
- RPKI State: Not evaluated
- IRR Consistency: Not evaluated
- DNSSEC Valid: Yes
- Operator Score: 0.2174 (Minimal)
## Observation History
21 observations recorded. Recent activity (June 2026) shows:
- Consistent high-abuse classification in neighborhood
- Geolocation validation failures persisting
- No changes in ownership or threat persistence
## Recommended Actions
Based on risk profile, the following defensive measures are recommended:
Firewall Rules:
- iptables: `iptables -A INPUT -s 148.113.128.65 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 148.113.128.65 drop`
- nginx: `deny 148.113.128.65;`
WAF/Cloud Services:
- Cloudflare WAF: Block with expression `ip.src eq 148.113.128.65`
- AWS WAF: Add `148.113.128.65/32` to protected resources
## Intelligence Conclusion
This IP operates within a high-abuse hosting environment with geolocation inconsistencies. No active malicious indicators present, but the neighborhood context warrants monitoring. If the IP appears in traffic analysis, blocking is recommended unless legitimate business relationship exists. The lack of open services suggests the IP is not actively serving, but the hosting environment classification indicates potential for abuse by other peers in the subnet.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059693 |
| CIDR Block | 148.113.128.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca014-san65.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca014-san65.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 23% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-12 21:54:00 UTC |
| Last Seen | 2026-06-27 22:00:06 UTC |
| Profile Built | 2026-06-28 16:05:11 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 27 |
Full dossier details are available via our API.