IP Intelligence Briefing: 148.113.130.252
Date: 2026-06-10
---
**1. Basic Profile**
- Risk Score: Moderate (50/100)
- Provider: OVH (ASN 16276)
- Organization: Ahrefs Pte Ltd (OVH-CUST-281059688)
- Geolocation:
- Country: Canada (CA)
- City: Singapore (inferred via geolocation sources)
- Coordinates: Latitude 56.13, Longitude -106.35 (approximate)
- Network Role: Cloud compute infrastructure (OVH-hosted, no residential/mobile origin)
---
**2. Threat Indicators**
- Malicious Activity: No detected threats, abuse, or spam sources.
- DNS Associations:
- Linked to `proxy-ca009-san252.ahrefs.net` (Ahrefs subdomain).
- No email authentication (SPF/DKIM) or TLS certificate anomalies.
- Historical Observations:
- Consistent geolocation and network attributes since 2026-06-01.
- No spikes in threat signals or DNS changes.
---
**3. Network Relationships**
- Subnet: 148.113.130.0/24
- Key Relationships:
- Same Network: 252 IPs in subnet (127 active, 88 flagged as high/medium risk).
- DNS: Direct ties to Ahrefs infrastructure.
- Provider: OVH CloudCompute (AS16276).
---
**4. Neighborhood Analysis**
- Subnet Abuse Density: 34.92% (mixed risk profile).
- Neighbor Risk Distribution:
- Low Risk: 77 IPs (avg. score 25).
- Medium Risk: 22 IPs (avg. score 50).
- High Risk: 0 IPs.
- Notable Neighbors:
- 148.113.130.0/24 (OVH infrastructure, no malicious signals).
---
**5. Historical Trends**
- Stability: No recent changes in ownership or network configuration.
- Threat Persistence: No observed malicious persistence or campaign activity.
- Geolocation Consistency: Canada (CA) reported across multiple sources.
---
**6. Recommendations**
- Monitoring: Track subnet abuse density (34.92%) for potential lateral movement.
- DNS: Monitor Ahrefs subdomains for unexpected traffic patterns.
- Firewall: Allow traffic to 148.113.130.252/24 unless associated with specific threats.
Note: No direct malicious activity detected. Contextual risks arise from the subnetβs mixed risk profile.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059688 |
| CIDR Block | 148.113.130.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca009-san252.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca009-san252.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 34% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 23% | 1 | 2 |
| geolocation | 19% | 2 | 2 |
| Overall | 20% | 10 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-25 18:47:07 UTC |
| Last Seen | 2026-06-29 01:54:52 UTC |
| Profile Built | 2026-06-29 07:57:54 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 20 |
Full dossier details are available via our API.