# IP Intelligence Briefing: 148.113.130.6/32
## Executive Summary
Target IP 148.113.130.6 is a moderate-risk infrastructure endpoint associated with OVH cloud hosting, resolving to Ahrefs proxy infrastructure. The IP operates within a high-abuse subnet with elevated peer activity and exhibits geolocation inconsistencies. No active threat indicators detected at time of analysis.
## Host Identity & Ownership
- IP Address: 148.113.130.6/32
- Risk Score: 40 (Moderate Risk)
- ASN: 16276 (OVH)
- Organization: Dmytro, Ahrefs Pte Ltd
- Network Block: 148.113.130.0/24
- Infrastructure Type: CloudCompute/Hosting
## Network Classification
- Provider: OVH
- Infrastructure Type: CloudCompute
- Classification: Hosting
- Connection Type: No services detected (firewalled)
- Tor/Proxy/VPN: Negative indicators
## Geolocation Analysis
- Reported Country: Canada (CA)
- Geolocation Confidence: Low (geoPlausible: false)
- Anomaly: RTT violation detectedβmeasured RTT of 27-35ms inconsistent with 6,082km distance from probe origin (minimum possible RTT: 121.6ms)
- Forward Resolution: proxy-ca009-san6.ahrefs.net
## Neighborhood Assessment
- Subnet: 148.113.130.0/24
- Abuse Density: 0.668 (High Abuse Classification)
- Active Siblings: 209 of 256 total
- Threat Siblings: 171
- Inherited Risk: 26
## Observed Signals
Analysis captured 22 signal observations. Recent infrastructure signals consistently classify the IP as cloud-hosting infrastructure. A single DNSBL listing recorded across 8 total lists. No active threat campaigns or known attacker associations detected.
## Relationships
Target IP shares network relationship with multiple OVH-CUST-281059688 network entries, indicating shared cloud infrastructure with other Ahrefs proxy endpoints.
## Recommended Security Actions
No automated recommendations generated due to moderate risk profile. However, the following firewall rules are available for deployment:
- iptables: `iptables -A INPUT -s 148.113.130.6 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 148.113.130.6 drop`
- nginx: `deny 148.113.130.6;`
- pfSense: `148.113.130.6/32`
- Cloudflare WAF: Block IP (expression: `ip.src eq 148.113.130.6`)
- AWS WAF: Add IP to block list (148.113.130.6/32)
## Assessment Notes
This IP operates within a high-abuse subnet environment. While the endpoint itself shows no active threat indicators, the elevated neighborhood risk score and geolocation inconsistencies warrant monitoring. The association with Ahrefs proxy infrastructure suggests potential use in web scraping, SEO analysis, or legitimate proxy services.
---
*Intelligence generated by IPDebrief. Rules should be combined with additional signals before deployment.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059688 |
| CIDR Block | 148.113.130.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca009-san6.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca009-san6.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 31% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 24% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-21 14:56:15 UTC |
| Last Seen | 2026-06-28 13:41:30 UTC |
| Profile Built | 2026-06-29 07:45:07 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 25 |
Full dossier details are available via our API.