INTELLIGENCE BRIEFING: 148.113.130.146/32
---
Classification: Moderate Risk / Cloud Infrastructure
Report Date: Current
Risk Score: 40/100
---
EXECUTIVE SUMMARY
IP address 148.113.130.146 is a cloud-hosted endpoint associated with Ahrefs Pte Ltd (OVH infrastructure) presenting moderate risk (score: 40). The IP is located within a subnet exhibiting high abuse density (0.5586), with 143 of 256 sibling IPs classified as threats. Despite this contextual risk, the endpoint itself is currently firewalled with no open services detected.
---
OWNERSHIP & INFRASTRUCTURE
- ASN: 16276 (OVH SAS)
- Organization: Dmytro, Ahrefs Pte Ltd
- Network: OVH-CUST-281059688 (148.113.130.0/24)
- Infrastructure Type: CloudCompute / Hosting
- Geolocation: Singapore (CA) โ 3,000 km accuracy radius
- Provider: OVH (Cloud provider)
---
THREAT INDICATORS
- Reputation: Moderate Risk
- DNSBL Listed: 1/8 lists
- Known Attacker: False
- Spam Source: False
- Tor Exit Node: False
- Threat Feeds: None
- Campaign Correlation: None detected
- Blacklist Count: 0
Historical Context:
- Total observations: 21
- Threat observation count: 1
- Persistently malicious: False
- Risk trend: Stable (no significant escalation)
---
NETWORK CONTEXT & NEIGHBORHOOD ANALYSIS
The endpoint resides in subnet 148.113.130.0/24 with elevated abuse characteristics:
- Subnet Abuse Density: 0.5586 (High)
- Active Siblings: 163 of 256
- Threat Siblings: 143
- Inherited Risk Score: 22
Risk distribution among neighbors:
- High risk: 0
- Medium risk: 98
- Low risk: 2
This indicates the subnet is predominantly utilized for legitimate enterprise hosting (Ahrefs infrastructure) but maintains a significant abuse footprint.
---
DNS & RESOLUTION DATA
- PTR Hostname: proxy-ca009-san146.ahrefs.net
- Forward Resolved: ahrefs.net (confirmed)
- Forward Hostnames: proxy-ca009-san146.ahrefs.net
- Forward Resolution Count: 1
- Email Auth: SPF: None, DMARC: None
---
SERVICES & NETWORK ROLE
- Open Ports: None detected
- Services: Firewalled / No Services
- CDN/Proxy/Vpn: False
- Mobile/Residential: False
- Infrastructure Status: Operational cloud endpoint
---
RELATIONSHIP GRAPH
- Total Relationships: 37
- Primary Association: Same Network (OVH-CUST-281059688) โ 32+ instances
- No external organization or certificate correlations beyond network boundaries
---
RECOMMENDED ACTIONS
Based on current risk profile and neighborhood context, consider the following:
Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 148.113.130.146 -j DROP
# nftables
nft add rule inet filter input ip saddr 148.113.130.146 drop
```
WAF/Proxy Recommendations:
- Cloudflare WAF: Block with risk score 40
- AWS WAF: Block CIDR 148.113.130.146/32
- PFSense: Block 148.113.130.146/32
- Nginx: deny 148.113.130.146
Assessment: Blocking is recommended due to subnet-level abuse density, though the endpoint shows no active malicious indicators. Monitor for changes in threat status.
---
ENDNOTES
This IP should be treated with caution due to subnet abuse characteristics. While the endpoint itself is not actively malicious, the high-density abuse environment suggests potential for compromise or misuse. SOC teams should monitor for any changes in DNS, port, or threat indicators.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059688 |
| CIDR Block | 148.113.130.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca009-san146.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca009-san146.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 23% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-21 14:56:15 UTC |
| Last Seen | 2026-06-28 13:38:58 UTC |
| Profile Built | 2026-06-29 07:42:48 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 25 |
Full dossier details are available via our API.