Threat Intelligence Briefing: IP Address 148.113.130.130/32
Summary:
The IP address 148.113.130.130/32 is a publicly routable IPv4 address managed by a specific Autonomous System (AS). This IP has been associated with multiple online services, which have varied over time, indicating dynamic usage patterns typical of cloud-based or managed hosting environments.
Observation History:
- The IP address has been observed in association with various online services, including web hosting and content delivery networks. These services have shown changes in domain associations over the observed period, which is common in environments that dynamically allocate IP addresses to different clients.
- The service level and nature of traffic associated with the IP address have demonstrated variability, which aligns with the characteristics of managed hosting environments where IPs are leased to different clients.
Relationships and Network Associations:
- The IP address is associated with a specific AS that operates globally, providing a range of network services, including web hosting, cloud services, and content delivery. This AS is known for its extensive infrastructure and services that cater to both individual consumers and enterprise clients.
- The IP address has been linked to several domains over time, suggesting its use for hosting multiple websites or services. These domains have varied in purpose, including e-commerce, informational sites, and online services.
Neighborhood Data:
- The IP address resides within a network block managed by the aforementioned AS, which includes other IPs with similar usage patterns. This block is known for its dynamic IP allocation, supporting a wide array of online services.
- The network neighborhood analysis indicates that the IP address shares its AS with other IPs that are also used for web hosting and cloud services, reinforcing the managed hosting environment hypothesis.
Actionable Insights:
- Given the dynamic nature of the IP address's associations and the managed hosting environment, it is advisable for SOC teams to monitor for any anomalies or suspicious activities, such as unexpected traffic spikes or patterns indicative of potential compromise.
- Regularly update threat intelligence feeds with the latest domain associations linked to this IP to ensure timely detection of any malicious activities.
- Consider implementing network-based monitoring tools to track changes in traffic patterns associated with this IP, as this can help in early detection of potential security incidents.
Conclusion:
The IP address 148.113.130.130/32 is part of a managed hosting environment, with its usage characterized by dynamic allocation and varied service associations. Continuous monitoring and analysis of traffic patterns and domain associations are recommended to maintain network security and detect potential threats.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059688 |
| CIDR Block | 148.113.130.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca009-san130.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca009-san130.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 22% | 1 | 2 |
| geolocation | 33% | 2 | 3 |
| Overall | 22% | 10 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-18 09:23:33 UTC |
| Last Seen | 2026-06-28 06:52:30 UTC |
| Profile Built | 2026-06-29 00:56:54 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 24 |
Full dossier details are available via our API.