# IP Intelligence Briefing: 148.113.130.40
## Executive Summary
IP 148.113.130.40 is classified as Moderate Risk with a risk score of 50. The address is hosted on OVH infrastructure (ASN 16276) and is associated with the domain ahrefs.net. The IP exhibits cloud hosting characteristics with no open services detected.
## Ownership and Network Classification
- Organization: Dmytro, Ahrefs Pte Ltd
- Netname: OVH-CUST-281059688
- ASN: 16276 (OVH SAS)
- CIDR Block: 148.113.130.0/24
- RIR: ARIN
- Infrastructure Type: CloudCompute (Hosting provider)
- Geolocation: Consensus indicates Singapore, with Canadian coordinates also reported
## Technical Profile
- DNS Resolution: Forward resolution to proxy-ca009-san40.ahrefs.net; reverse DNS PTR record confirmed
- Open Ports: None detected (service purpose: Firewalled / No Services)
- SSL/TLS: No certificates detected
- HTTP Services: Inactive
- DNSSEC: Valid
## Threat Indicators
- Blacklist Status: Listed on 2 DNSBL entries out of 8 total checks
- Threat Classifications: Not Tor exit node, not known attacker, not spam source
- Abuse Confidence Score: Not available
- Campaign Correlation: No matching campaigns or correlated IPs identified
- Known Threat Feeds: None
## Neighborhood Analysis
The IP resides in subnet 148.113.130.0/24 with the following characteristics:
- Abuse Density: 0.6055 (High abuse classification)
- Subnet Status: 174 active siblings out of 256 total IPs
- Threat Siblings: 155 threat-related IPs identified in the /24
- Inherited Risk Score: 24
- Neighbor Risk Distribution: 100 medium-risk neighbors, 0 high-risk, 0 low-risk
## Historical Observation
21 total observations recorded with the following timeline:
- Most recent: 2026-06-28T22:26:24
- Previous: 2026-06-20T20:19:47
- Threat Persistence: 0 days (not persistently malicious)
- Ownership Changes: 0 changes
- Threat Observation Count: 0
Signal scores consistently show minimal operator scores (0.087-0.2174) with low confidence levels (0.19-0.85).
## Control Plane Data
- BGP Prefix: 148.113.128.0/17
- Route Stability: Unstable (isRouteStable: false)
- RPKI State: Not available
- IRR Consistency: Not available
- Route Changes (30d): 0
- DNSSEC Valid: True
- CAA Records: Present
- MOAS: False
## SOC Actionable Recommendations
1. Monitor for Service Activation: IP currently shows no open ports. Monitor for service emergence.
2. DNSBL Review: Investigate the 2 DNSBL listings for this IP to determine blocking rationale.
3. Subnet Context: The /24 subnet shows elevated abuse density (0.6055) with 155 threat siblings. Consider applying subnet-wide monitoring policies.
4. Geolocation Discrepancy: RTT validation shows 6082km distance with 27ms minimum RTT, indicating a geographic inconsistency that warrants verification.
5. Ahrefs Association: The PTR hostname (proxy-ca009-san40.ahrefs.net) indicates legitimate use for web crawling or SEO services. Verify if this aligns with expected traffic patterns.
## Risk Assessment
This IP represents a Moderate Risk asset with legitimate cloud hosting characteristics. The primary concern is the high abuse density of the parent subnet and DNSBL listings. No active malicious indicators were identified. Recommended approach: Monitor rather than block, with awareness of the subnet's elevated risk profile.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059688 |
| CIDR Block | 148.113.130.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca009-san40.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca009-san40.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 39% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 22% | 1 | 2 |
| geolocation | 39% | 2 | 3 |
| Overall | 24% | 10 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-23 18:28:40 UTC |
| Last Seen | 2026-06-28 22:26:25 UTC |
| Profile Built | 2026-06-29 16:29:22 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 24 |
Full dossier details are available via our API.