IP INTELLIGENCE BRIEFING: 148.113.130.107
Classification: Moderate Risk | Risk Score: 40/100 | Status: Active
---
**Ownership & Infrastructure**
- Organization: Dmytro, Ahrefs Pte Ltd (OVH customer)
- ASN: 16276 (OVH)
- CIDR Block: 148.113.130.0/24
- Network Role: Hosting provider environment; no open services detected
- Classification: isHosting=true; servicePurpose="Firewalled / No Services"
**Geolocation Analysis**
- Reported Location: Canada (CA) with coordinates 43.63°N, -79.37°W
- Geo Validation: โ ๏ธ VIOLATION DETECTED
- Claimed distance: 6,082 km from probe origin
- Minimum possible RTT: 121.6 ms
- Observed RTT: 23.0 ms
- Conclusion: Geolocation data is implausible; likely false location reporting
**Threat Intelligence**
- Known Threats: None identified
- Blacklist Status: Listed on 1 of 8 DNSBL feeds
- Threat Indicators: No known campaigns, attacker signatures, or spam source activity
- Tor/Proxy: Not a Tor exit node; not classified as proxy or VPN
- Abuse Confidence: Inherited risk score of 20 from subnet context
**Subnet Context (148.113.130.0/24)**
- Abuse Density: 0.5195 (HIGH)
- Classification: high_abuse
- Active Siblings: 162 out of 256 total
- Threat Siblings: 133 IPs flagged as threats
- Risk Distribution: 97 medium-risk neighbors, 3 low-risk, 0 high-risk
- Inherited Risk: 20/100
**DNS & Network Behavior**
- PTR Record: proxy-ca009-san107.ahrefs.net
- Forward Resolution: Confirmed (ahrefs.net)
- Open Ports: None detected
- TLS/Certificates: Not available
- HTTP Status: No active web services
**Temporal Analysis**
- Observations: 20 recent signals collected
- Ownership Changes: 0 changes recorded
- Threat Persistence: Single observation event; not persistently malicious
- Route Stability: Route changes observed in 30-day window
**Recommended Actions**
Based on moderate risk score (40) and high-abuse subnet context:
```bash
# Firewall Block Rules
iptables -A INPUT -s 148.113.130.107 -j DROP
nft add rule inet filter input ip saddr 148.113.130.107 drop
# Application Layer
nginx: deny 148.113.130.107;
pfSense: 148.113.130.107/32
# WAF Integration
Cloudflare WAF: Block with expression: ip.src eq 148.113.130.107
AWS WAF: Add 148.113.130.107/32 to block list
```
---
**Analyst Assessment**
This IP is hosted within OVH's high-abuse subnet (148.113.130.0/24), which shows significant abuse density. However, the specific IP has no direct threat indicators and is associated with legitimate Ahrefs infrastructure. The geolocation data shows clear inconsistencies suggesting potential location spoofing.
Recommended Action: Monitor traffic patterns from this IP. Given the moderate risk score (40) and lack of direct threat indicators, consider blocking at network perimeter while maintaining observability. Subnet-level abuse context warrants heightened scrutiny for similar IPs within 148.113.130.0/24.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059688 |
| CIDR Block | 148.113.130.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca009-san107.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca009-san107.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 37% | 2 | 3 |
| Overall | 23% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-11 08:57:43 UTC |
| Last Seen | 2026-06-27 19:06:00 UTC |
| Profile Built | 2026-06-28 13:11:39 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 25 |
Full dossier details are available via our API.