## IP Intelligence Briefing: 167.114.139.45/32
Date: 2026-07-01
IP Address: 167.114.139.45/32
Risk Classification: Moderate Risk (Score: 40/100)
---
**Executive Summary**
IP 167.114.139.45 is a cloud hosting infrastructure address associated with Ahrefs Pte Ltd (OVH network). While the IP itself shows no active threat indicators, it resides within a /24 subnet (167.114.139.0/24) exhibiting high abuse density (0.7266). The address is currently firewalled with no open services detected. Recommended for monitoring and blocking at perimeter controls.
---
**Infrastructure Profile**
| Attribute | Value |
|---|---|
| **ASN/Provider** | 16276 (OVH) |
| **Organization** | Dmytro, Ahrefs Pte Ltd |
| **Network Block** | 167.114.139.0/24 |
| **Geolocation** | Montreal, QC, CA |
| **Infrastructure Type** | CloudCompute, Hosting |
| **Network Role** | Firewalled / No Services |
DNS Resolution: proxy-ca000-san45.ahrefs.net (ahrefs.net domain)
Service Status: No open ports detected
---
**Threat Assessment**
Current Threat Indicators:
- Abuse Confidence Score: None
- Blacklist Count: 1 (DNSBL listed)
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Active Campaigns: None
Geolocation Validation: GeoPlausible flag = FALSE. RTT analysis (28ms) contradicts physical distance from Montreal (5,597km), suggesting proxying or data inconsistency.
---
**Subnet Analysis (167.114.139.0/24)**
- Abuse Density: 0.7266 (High Abuse)
- Subnet Classification: high_abuse
- Total Siblings: 256
- Active Siblings: 221
- Threat Siblings: 186
- Inherited Risk Score: 29
Risk Distribution Across Subnet:
- High Risk: 0 IPs
- Medium Risk: 52 IPs
- Low Risk: 48 IPs
---
**Observation History**
- Total Observations: 22 signals
- Threat Persistence Days: 0
- Ownership Changes: 0
- Recent Activity: Consistent cloud/hosting classification observed. DNS records for ahrefs.net domain confirmed.
---
**Relationship Graph**
- Total Relationships: 33
- Primary Association: Same Network (OVH-CUST-281059679)
- No unusual entity associations detected
---
**Recommended Actions**
| Platform | Action |
|---|---|
| **Firewall (iptables/nftables)** | `iptables -A INPUT -s 167.114.139.45 -j DROP` |
| **Web Server (nginx)** | `deny 167.114.139.45;` |
| **Cloudflare WAF** | Block expression: `ip.src eq 167.114.139.45` |
| **AWS WAF** | Add 167.114.139.45/32 to blocked addresses |
Recommendation: Implement blocking rules at perimeter controls. Given the moderate risk score and high-abuse subnet environment, consider adding the entire /24 to a watchlist for correlation analysis.
---
**Analyst Notes**
1. The IP resolves to legitimate ahrefs.net infrastructure but operates in a high-abuse subnet environment
2. No direct threat activity observed on this specific address
3. Geographic validation failure warrants additional verification if traffic originates from this IP
4. Monitor for any changes in service availability or DNS configuration
Status: Monitor/Block
Confidence: Moderate
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059679 |
| CIDR Block | 167.114.139.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca000-san45.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca000-san45.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 32% | 1 | 3 |
| geolocation | 40% | 2 | 3 |
| Overall | 24% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-23 12:22:21 UTC |
| Last Seen | 2026-06-28 21:22:15 UTC |
| Profile Built | 2026-06-29 03:25:15 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.