# IP INTELLIGENCE BRIEFING
IP Address: 148.113.130.138/32
Classification: Moderate Risk (Score: 40/100)
Date: Current
Status: Active Cloud Infrastructure
---
## EXECUTIVE SUMMARY
The IP address 148.113.130.138 is a cloud computing endpoint hosted on OVH infrastructure (ASN 16276) for the organization "Dmytro, Ahrefs Pte Ltd." The IP resolves to the ahrefs.net domain and operates as a cloud-hosted proxy endpoint. While the individual IP shows moderate risk, the subnet demonstrates elevated abuse density typical of shared cloud environments. No direct attack indicators or malicious activity signatures were identified.
---
## OWNERSHIP AND INFRASTRUCTURE
| Attribute | Value |
|---|---|
| **ASN** | 16276 (OVH SAS) |
| **Organization** | Dmytro, Ahrefs Pte Ltd |
| **Netname** | OVH-CUST-281059688 |
| **Registration** | ARIN |
| **Infrastructure** | CloudCompute (OVH) |
| **Hosting** | Enabled |
| **IPv6** | Not detected |
Geolocation Discrepancy Alert:
Geolocation data indicates Singapore (CA), but RTT measurements show a 6082km distance with 27ms latencyβphysically impossible for this distance (minimum possible RTT: 121.6ms). This indicates unreliable or spoofed geolocation data.
---
## NETWORK ENVIRONMENT ASSESSMENT
Subnet: 148.113.130.0/24
Abuse Density: 0.6055 (High Abuse Classification)
Subnet Statistics:
- Total IPv4 Addresses: 256
- Active/Allocated: 168
- Threat-classified Siblings: 155
- Inherited Risk Score: 24
Neighbor Risk Profile:
All 100 sampled neighbors in the /24 subnet show medium risk (score: 40) with authority scores of 50. This indicates a shared infrastructure environment with consistent abuse characteristics across the subnet.
---
## THREAT INDICATORS
Direct Indicators:
- Blacklist Count: 0
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
Control Plane Data:
- DNSBL Listed: 1 of 8 total lists
- Operator Score: 0.2174 (Minimal)
- Route Stability: False
- IRR Consistency: Not verified
- Route Changes (30d): 0
Services:
- Open Ports: None detected
- HTTP/HTTPS: No services responding
- TLS Certificates: None
---
## DNS AND REVERSE LOOKUP
PTR Record: proxy-ca009-san138.ahrefs.net
Forward Resolution: ahrefs.net
DNSSEC: Valid
CAA Records: Present
Email Authentication: SPF/DMARC not configured
---
## OBSERVATION HISTORY
Total Observations: 21
Recent Activity:
- 2026-06-20: DNS resolution to ahrefs.net confirmed (confidence: 0.80)
- 2026-06-15: Subnet classified as "high_abuse" with 0.6055 abuse density
- 2026-06-15: Alienvault OTX geolocation showed US coordinates (37.751, -97.822) with zero threat flags
- 2026-06-15: Operator score labeled "Minimal" (0.2174)
Temporal Analysis:
- Ownership changes: 0
- Threat persistence days: 0
- Threat observation count: 1
- Persistently Malicious: No
---
## RELATIONSHIP MAPPING
Total Relationships: 36
Primary Relationship Type: Same Network (OVH-CUST-281059688)
Related Entities:
- Network: OVH-CUST-281059688 (multiple instances)
- No external hostnames, organizations, or certificate relationships detected beyond the network identifier
---
## RECOMMENDED ACTIONS
For SOC Analysts:
1. Monitor for Anomalies: Given the high-abuse subnet classification, monitor for unusual traffic patterns from this IP, particularly outbound connections or data exfiltration attempts.
2. Traffic Analysis: Apply behavioral analysis to determine if traffic aligns with legitimate ahrefs.net service patterns.
3. Geolocation Validation: The RTT/geo discrepancy warrants flagging for manual reviewβconsider blocking if this IP is being used to spoof geographic origin.
4. Subnet Context: Evaluate traffic in context of the broader /24 subnet; 155 threat-classified siblings suggest elevated peer risk.
5. DNSBL Monitoring: Track DNSBL listing status; current listing count of 1 out of 8 may indicate emerging reputation issues.
Firewall Rules (Recommended):
- Allow traffic only to known ahrefs.net domains
- Block port 80/443 if no services are confirmed
- Log all connections for behavioral analysis
- Consider rate limiting based on baseline traffic patterns
---
## RISK CONCLUSION
Overall Risk: MODERATE
Primary Concerns: Subnet abuse density and geolocation inconsistencies
Mitigation: Cloud infrastructure with no direct attack signatures; risks are environmental rather than IP-specific. Monitor for behavioral anomalies and verify legitimate traffic patterns.
Recommended Priority: LOW-MEDIUM (Monitor)
Threat Level: No active campaigns or known malicious activity detected.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059688 |
| CIDR Block | 148.113.130.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca009-san138.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca009-san138.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 32% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 32% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 24% | 10 | 15 |
| Data Coherence | Mixed Signals (60%) β 2 contradiction(s) |
| Attribution | Very Low (20%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
β Geo sources disagree on country: US, CA
π Observation Timeline π Live
| First Seen | 2026-05-23 12:22:03 UTC |
| Last Seen | 2026-06-28 21:04:15 UTC |
| Profile Built | 2026-06-29 03:07:06 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.