# IP Intelligence Briefing: 148.113.130.220
Classification: Moderate Risk | Status: Active Infrastructure
## Executive Summary
IP 148.113.130.220 operates as a cloud-based hosting resource under OVH infrastructure (ASN 16276). The IP presents moderate risk (score 50) with no active threat indicators detected. Geolocation data reveals significant inconsistencies that warrant validation. The subnet exhibits high abuse density (0.6055), suggesting elevated risk from neighboring addresses.
## Ownership and Infrastructure
| Attribute | Value |
|---|---|
| ASN | 16276 |
| Organization | Dmytro, Ahrefs Pte Ltd |
| Network Name | OVH-CUST-281059688 |
| CIDR Block | 148.113.130.0/24 |
| RIR | ARIN |
| Provider | OVH |
| Infrastructure Type | CloudCompute |
| Service Status | Firewalled / No Services |
## Geolocation Analysis
The IP's geolocation data contains a critical validation failure:
- Reported Location: Singapore (6082 km from Canada)
- Country Code: CA (Canada)
- Validation Status: INVALID
- Evidence: Round-trip time (RTT) of 27ms contradicts the 121.6ms minimum required for 6082km distance. This geolocation violation suggests either spoofed data or routing anomalies.
Recommendation: Correlate with additional geolocation sources and validate physical location against known infrastructure deployments.
## DNS Resolution
| Field | Value |
|---|---|
| PTR Hostname | proxy-ca009-san220.ahrefs.net |
| Forward Resolution | proxy-ca009-san220.ahrefs.net |
| Domain | ahrefs.net |
| Forward Confirmed | No |
| SPF Record | Not Configured |
| DMARC Record | Not Configured |
## Network Risk Profile
| Metric | Value |
|---|---|
| Risk Score | 50 (Moderate) |
| Abuse Confidence | Not Detected |
| Blacklist Count | 0 |
| DNSBL Listed | 2 of 8 lists |
| Operator Score | 0.2174 (Minimal) |
| Route Stability | False |
| Known Campaigns | None |
## Subnet Context (148.113.130.0/24)
- Abuse Density: 0.6055 (High)
- Classification: high_abuse
- Active Siblings: 163 of 256
- Threat Siblings: 155
- Neighborhood Risk: Elevated risk inherited from subnet abuse patterns
## Historical Observations
Signal history reveals 20 observations with key patterns:
- Most Recent: 2026-06-28 (Cloud infrastructure classification, confidence 0.90)
- Previous: 2026-06-20 (Geolocation observations showing Canada)
- Threat Persistence: 0 days
- Persistence Classification: Not persistently malicious
## Threat Indicators
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Threat Feeds: None
- Known Campaigns: None
## Recommended Actions
1. Monitor Neighbor IPs: The subnet (148.113.130.0/24) shows high abuse density. Review adjacent IPs for correlated malicious activity.
2. Validate Geolocation: Investigate the Singapore/Canada geolocation discrepancy through additional probing or collaboration with upstream providers.
3. Traffic Baseline: Establish baseline traffic patterns given the firewalled status and lack of open services.
4. DNSBL Monitoring: Track the 2 DNSBL listings for changes that may indicate emerging reputation issues.
## Conclusion
IP 148.113.130.220 represents a cloud hosting resource with moderate risk characteristics. While no active threat indicators are present, the subnet's high abuse density and geolocation validation failures warrant ongoing monitoring. No immediate blocking is recommended, but maintain awareness of neighborhood risk patterns.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059688 |
| CIDR Block | 148.113.130.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca009-san220.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca009-san220.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 39% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 21% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 26% | 10 | 14 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-21 20:59:18 UTC |
| Last Seen | 2026-06-28 15:21:01 UTC |
| Profile Built | 2026-06-29 03:25:15 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 24 |
Full dossier details are available via our API.