IP Intelligence Briefing: 148.113.130.9
Date: 2026-06-13
---
**1. Core Profile**
- Risk Score: 25 (Low Risk)
- Ownership:
- ASN: 16276 (OVH)
- Organization: Ahrefs Pte Ltd (Hosting provider)
- Network: 148.113.130.0/24
- Geolocation:
- Country: Canada (CA)
- City: Singapore
- Plausibility: False (RTT anomaly detected; 22ms vs. expected 121.6ms for 6,082km)
- Threat Indicators:
- No malicious activity, spam, or known attacker associations.
- No DNS-based threats or blacklisted domains.
---
**2. Network Context**
- Network Role:
- Cloud Hosting: Part of OVH's infrastructure (OVH-CUST-281059688).
- Subnet: 148.113.130.0/24 (252 IPs).
- Subnet Risk:
- Abuse Density: 34.92% (moderate).
- Threat Siblings: 88 IPs (14 medium-risk, 86 low-risk).
- Active Siblings: 127 IPs.
- Routing:
- BGP Prefix: 148.113.128.0/17.
- Route Stability: Unstable (0 route changes in 30 days).
---
**3. Historical Observations**
- Recent Activity:
- DNS resolution for `proxy-ca009-san9.ahrefs.net` (ahrefs.net).
- Subnet analysis showing consistent abuse density.
- Geo-Validation:
- RTT Anomaly: 22ms vs. expected 121.6ms for 6,082km distance.
- Geolocation Source: Single probe (5 probes total).
---
**4. Relationships & Neighbors**
- Linked Entities:
- Same Network: OVH-CUST-281059688 (100+ IPs).
- DNS: `proxy-ca009-san9.ahrefs.net` (no email auth records).
- Neighbor Risk:
- Total Neighbors: 100 (14 medium-risk, 86 low-risk).
- Abuse Density: 34.92% (mixed classification).
---
**5. Actionable Insights**
- No Immediate Threat:
- No malicious indicators, spam, or known attacker associations.
- Monitor Subnet:
- The 148.113.130.0/24 subnet has moderate abuse density. Monitor for new risky IPs.
- Verify Geolocation:
- Investigate the geo-plausibility discrepancy (22ms RTT vs. 6,082km distance).
- Network Segmentation:
- Ensure cloud-hosted services (OVH) are properly segmented to limit lateral movement.
---
Conclusion:
148.113.130.9 is associated with Ahrefs Pte Ltd (OVH hosting) and shows no direct malicious activity. However, the subnetβs moderate abuse density and geo-plausibility anomaly warrant further investigation. SOC teams should monitor the subnet for emerging risks and validate geolocation accuracy.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059688 |
| CIDR Block | 148.113.130.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca009-san9.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca009-san9.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 32% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 22% | 1 | 2 |
| geolocation | 30% | 2 | 3 |
| Overall | 21% | 10 | 13 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:03:45 UTC |
| Last Seen | 2026-06-26 23:54:55 UTC |
| Profile Built | 2026-06-27 14:06:37 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 26 |
Full dossier details are available via our API.