IP Intelligence Briefing: 167.114.139.42/32
*Generated via IPDebrief Analysis*
---
**1. Core Profile**
- Risk Score: Moderate (50/100)
- Ownership:
- ISP: OVH (ASN 16276)
- Organization: Dmytro, Ahrefs Pte Ltd
- Subnet: 167.114.139.0/24
- Geolocation: Montreal, Canada (QC)
- Network Role: Cloud hosting infrastructure (OVH)
- Threat Indicators:
- No direct malicious activity (no known campaigns, spam, or abuse confidence scores).
- DNS Associations: Linked to `proxy-ca000-san42.ahrefs.net` (Ahrefs infrastructure).
- DNSBL Listings: 2/8 lists (potential spam or abuse risks).
---
**2. Observation History**
- Recent Activity (2026-06-10):
- Subnet abuse density increased to 0.71 (high abuse classification).
- Inherited risk score: 28 (moderate).
- Routing Stability: Unstable (route changes detected).
- DNSSEC Validity: Confirmed.
- CAA Records: Validated.
---
**3. Relationships**
- Network:
- Same subnet (`167.114.139.0/24`) with 251 sibling IPs (123 flagged as threats).
- DNS:
- Resolves to `proxy-ca000-san42.ahrefs.net` (Ahrefs).
- Ownership:
- Shared with OVHβs `OVH-CUST-281059679` network.
---
**4. Neighborhood Analysis**
- Subnet Abuse Density: 49% (moderate risk).
- Neighbor Risk Distribution:
- 73 IPs: Medium risk (40β50 score).
- 27 IPs: Low risk.
- 0 IPs: High risk.
- Notable Neighbors:
- IPs like `167.114.139.0` and `167.114.139.4` show similar risk profiles.
---
**5. Threat Context**
- No Direct Malicious Activity: No indicators of malware, phishing, or exploitation.
- Subnet Risks:
- DNSBL Listings: 2/8 (potential spam or abuse risks).
- High Abuse Density: Subnet contains both benign and malicious IPs.
- Cloud Hosting: Likely a server node for Ahrefsβ infrastructure, with no exposed services (no open ports, no TLS certs).
---
**6. Recommendations**
- Monitor Subnet: Due to high abuse density, investigate neighboring IPs for suspicious behavior.
- Block Subnet: Consider blocking `167.114.139.0/24` if the subnetβs risk profile escalates.
- Verify DNS: Confirm `proxy-ca000-san42.ahrefs.net` is legitimate and not a phishing alias.
- Check for Anomalies: Monitor for unexpected DNS resolution or traffic patterns from this subnet.
---
*End of Briefing*
*Generated by IPDebrief (© 2026 Jason Alberino)*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059679 |
| CIDR Block | 167.114.139.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | β |
π DNS Intelligence
| PTR | proxy-ca000-san42.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca000-san42.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 22% | 2 | 4 |
| ownership | 15% | 2 | 2 |
| reputation | 23% | 1 | 2 |
| geolocation | 26% | 2 | 2 |
| Overall | 23% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-24 00:31:30 UTC |
| Last Seen | 2026-06-28 23:16:25 UTC |
| Profile Built | 2026-06-29 05:17:47 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 24 |
Full dossier details are available via our API.