IP INTELLIGENCE BRIEFING: 148.113.130.100/32
Classification: MODERATE RISK (Score: 40/100)
---
EXECUTIVE SUMMARY
IP 148.113.130.100 is a cloud-based hosting address owned by OVH (ASN 16276) under organization "Dmytro, Ahrefs Pte Ltd." The address resolves to aforens.net domain (proxy-ca009-san100.ahrefs.net), indicating legitimate Ahrefs infrastructure. However, the IP operates within a high-abuse density subnet (148.113.130.0/24) with 60.55% abuse density and 155 threat-identified sibling IPs. Geographic inconsistencies and DNSBL listings warrant monitoring.
---
OWNERSHIP & INFRASTRUCTURE
- Provider: OVH (Cloud compute infrastructure)
- Organization: Dmytro, Ahrefs Pte Ltd
- Network Block: 148.113.130.0/24
- Classification: Cloud hosting environment
- Services: Firewalled / No open ports detected
- Control Plane: BGP prefix 148.113.128.0/17, origin ASN 16276
---
GEOGRAPHIC DISCREPANCIES
- Reported Country: Canada (CA)
- Reported City: Singapore
- Geolocation Validation: FAILED
- RTT Violation: Measured 27ms vs. minimum expected 121.6ms for 6,082km distance
- Assessment: Geographic data is inconsistent. The IP appears to be hosted in Asia-Pacific region but misreported as North American.
---
THREAT INDICATORS
- Risk Score: 40/100 (Moderate)
- DNSBL Listings: 1 of 8 total lists
- Known Threats: None directly associated
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Threat Persistence: 0 days (not persistently malicious)
---
NEIGHBORHOOD CONTEXT
- Subnet: 148.113.130.0/24
- Abuse Density: 0.6055 (HIGH ABUSE CLASSIFICATION)
- Total Siblings: 256 IPs
- Active Siblings: 163
- Threat-Associated Siblings: 155
- Inherited Risk Score: 24/100
The subnet exhibits elevated abuse activity. While the specific IP shows no direct malicious indicators, the neighborhood context suggests a high-risk hosting environment.
---
OBSERVATION HISTORY
- Total Observations: 19 signals tracked
- Recent Activity: Last observed 2026-06-20
- Ownership Changes: 0 (stable)
- Threat Observation Count: 1
- Signal Types: Provider classification, DNS resolution, operator score, threat assessment
---
RELATIONSHIP GRAPH
- Total Relationships: 46 entries
- Primary Association: OVH-CUST-281059688 network block (46 relationship entries)
- Network Classification: Same network associations consistent
---
RECOMMENDED ACTIONS
IMMEDIATE: Consider Blocking
The combination of high-abuse neighborhood, DNSBL listing, and geographic inconsistencies suggests elevated risk despite legitimate Ahrefs association.
Firewall Rules:
- iptables: `iptables -A INPUT -s 148.113.130.100 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 148.113.130.100 drop`
- nginx: `deny 148.113.130.100;`
Cloud Platforms:
- Cloudflare WAF: Block IP 148.113.130.100 (Expression: `ip.src eq 148.113.130.100`)
- AWS WAF: Add 148.113.130.100/32 to IP set with description "IPDebrief risk 40"
---
INTELLIGENCE NOTE
While the IP resolves to legitimate Ahrefs infrastructure, the subnet abuse context and geographic inconsistencies indicate this may be a shared hosting environment where legitimate services coexist with malicious actors. Consider implementing subnet-level blocking (148.113.130.0/24) if threat correlation with neighborhood IPs is observed. Monitor for any changes in service patterns or new threat indicators.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059688 |
| CIDR Block | 148.113.130.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca009-san100.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca009-san100.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 21% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 26% | 10 | 14 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-21 20:59:18 UTC |
| Last Seen | 2026-06-28 15:19:13 UTC |
| Profile Built | 2026-06-29 03:22:57 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 23 |
Full dossier details are available via our API.