IP Intelligence Briefing: 148.113.130.113
Date: 2026-06-08
---
**1. Core Profile**
- Risk Score: 50 (Moderate Risk)
- Ownership: Registered to Ahrefs Pte Ltd (OVH ASN 16276).
- Geolocation: Singapore, Canada (latitude 56.13, longitude -106.35).
- Network Role: CloudCompute (OVH infrastructure).
- Threat Indicators: No malicious indicators (no blacklists, campaigns, or spam).
---
**2. Network Behavior**
- Subnet: 148.113.130.0/24
- Subnet Abuse Density: 0.2789 (moderate risk).
- Neighbor Risk Distribution:
- High Risk: 0 IPs
- Medium Risk: 58 IPs
- Low Risk: 42 IPs
- Subnet Classification: "Mixed" (combination of legitimate and risky IPs).
---
**3. Threat Observations**
- Historical Signals:
- Low-confidence scans (ports scanned, but no open services detected).
- DNS resolution to proxy-ca009-san113.ahrefs.net (Ahrefs hostname).
- No DNSBL listings or malware campaigns linked.
- TLS/HTTP: No active services (no open ports, no TLS certs, no HTTP banners).
---
**4. Relationships**
- DNS Associations: Linked to proxy-ca009-san113.ahrefs.net (Ahrefs).
- Network Affiliation: Part of OVH-CUST-281059688 (OVH customer subnet).
- BGP: Prefix 148.113.128.0/17 with no route anomalies.
---
**5. Recommendations**
- Monitor Subnet: The 148.113.130.0/24 subnet has a moderate abuse density. Investigate medium-risk neighbors for potential lateral movement or compromised hosts.
- Verify DNS: Confirm DNS resolution to proxy-ca009-san113.ahrefs.net is legitimate (Ahrefs is a known cloud provider).
- Baseline Traffic: Since no active services are detected, ensure no unexpected outbound traffic is observed.
- Firewall Rules: Consider allowing traffic to this IP if itβs a legitimate cloud server, but block high-risk neighbors in the subnet.
---
Conclusion: This IP is part of a legitimate cloud infrastructure (Ahrefs) with no current malicious activity. However, the subnet contains a mix of risky and benign IPs, warranting closer monitoring. No immediate action is required, but ongoing observation is advised.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059688 |
| CIDR Block | 148.113.130.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca009-san113.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca009-san113.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 39% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 22% | 1 | 2 |
| geolocation | 33% | 2 | 3 |
| Overall | 23% | 10 | 13 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-19 21:39:13 UTC |
| Last Seen | 2026-06-28 09:38:39 UTC |
| Profile Built | 2026-06-29 03:43:35 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 24 |
Full dossier details are available via our API.