IP Intelligence Briefing: 148.113.130.208/32
*Generated via IPDebrief tools: Profile, History, Relationships, & Neighborhood Analysis*
---
**Key Findings**
1. Ownership & Network Role
- Provider: OVH (ASN 16276)
- Network: Subnet `148.113.130.0/24`, classified as "mixed" (normal + potential abuse).
- Purpose: Cloud compute instance (OVH hosting), no residential/mobile traffic.
- DNS: Linked to `proxy-ca009-san208.ahrefs.net` (Ahrefs Pte Ltd).
2. Geolocation Discrepancy
- Reported Country: Canada (CA)
- City: Singapore (via DNS resolution)
- RTT Anomaly: 27ms latency inconsistent with 6,082km distance (minimum plausible RTT: 121.6ms).
- GeoPlausibility: False (likely misconfigured or spoofed location).
3. Threat Indicators
- No Direct Malicious Activity: No indicators of spam, attacks, or known campaigns.
- Subnet Risk: 29% abuse density; 74 of 252 sibling IPs show threat activity.
- DNS Security: DNSSEC valid, but no email authentication (SPF/DKIM/MX) detected.
4. Historical Observations
- Recent Activity: 18 signals recorded (June 1โ10, 2026).
- Notable:
- DNS resolution and route validation anomalies (RTT mismatch).
- Subnet abuse density flagged as "mixed" with inherited risk.
5. Relationships
- Connected Entities:
- Same network (`OVH-CUST-281059688`).
- DNS hostname `proxy-ca009-san208.ahrefs.net` (Ahrefs).
- No Known Campaigns or Malware Signatures.
---
**Actionable Insights**
- Monitor Subnet: The `/24` subnet has 29% abuse density; prioritize monitoring high-risk siblings (74/252).
- Investigate Geolocation Discrepancy: The RTT anomaly and conflicting location data may indicate misconfiguration or spoofing.
- Verify DNS Configuration: Ensure `proxy-ca009-san208.ahrefs.net` is legitimate and not used for obfuscation.
- Check for Anomalies: No direct threats, but the cloud-hosted IPโs mixed subnet and RTT issues warrant closer scrutiny.
---
**Recommendations**
- SOC Analyst Actions:
- Correlate this IP with internal logs for unusual traffic patterns.
- Validate DNS resolution and geolocation data with additional tools.
- Flag the subnet for deeper analysis due to inherited risk.
- Firewall Rules:
- Consider blocking high-risk siblings in the `148.113.130.0/24` subnet if traffic is suspicious.
Note: This IP appears legitimate but requires ongoing monitoring due to conflicting geolocation data and subnet risk.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059688 |
| CIDR Block | 148.113.130.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca009-san208.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca009-san208.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 23% | 1 | 2 |
| geolocation | 40% | 2 | 3 |
| Overall | 24% | 10 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-23 18:28:40 UTC |
| Last Seen | 2026-06-28 22:25:37 UTC |
| Profile Built | 2026-06-29 04:28:14 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 23 |
Full dossier details are available via our API.