INTELLIGENCE BRIEFING: 168.100.149.118/32
Classification: Low Risk - Infrastructure IP
Date: [Current Analysis Date]
---
EXECUTIVE SUMMARY
The subject IP address 168.100.149.118 is classified as a low-risk (risk score: 20) infrastructure endpoint belonging to Ahrefs Pte Ltd (ASN 140577). The IP resolves to proxy-us002-san18.ahrefs.net and operates within the AHREFS-US network. No active threat indicators, blacklist entries, or malicious campaign associations were detected. The IP maintains a low-risk profile with zero open services and no evidence of abuse.
---
OWNERSHIP & NETWORK CONTEXT
- Organization: Ahrefs Pte Ltd administrator
- ASN: 140577
- Network: AHREFS-US
- Geolocation: Ashburn, VA, US (Geo validation flagged: RTT anomaly detectedβ26ms observed vs 126.2ms minimum possible for stated distance)
- Control Plane: BGP prefix 168.100.144.0/20; route stability: false
---
THREAT INDICATORS
- Risk Score: 20 (Low Risk)
- Blacklist Count: 0
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Threat Feeds: None
- Abuse Confidence Score: Not applicable (no abuse signals)
---
NETWORK ROLE & SERVICES
- Service Purpose: Firewalled / No Services
- Open Ports: None detected
- DNS Records: Forward resolution to proxy-us002-san18.ahrefs.net confirmed
- Email Authentication: SPF: No, DMARC: No
- SSL/TLS: No certificates observed
---
NEIGHBORHOOD ANALYSIS (168.100.149.0/24)
- Total Siblings: 230
- Active Siblings: 80
- Threat Siblings: 88
- Abuse Density: 0.3826 (mixed classification)
- Risk Distribution: High: 0, Medium: 17, Low: 83
- Inherited Risk: 15
The /24 subnet shows mixed classification with a moderate threat presence. However, the subject IP itself maintains a low-risk posture independent of neighborhood context.
---
RELATIONSHIP MAPPING
- Same Network: AHREFS-US (multiple associations)
- DNS Associations: proxy-us002-san18.ahrefs.net
- Total Relationships: 36
---
OBSERVATION HISTORY
- Total Signals: 21 observations
- Recent Risk Signals: Minimal to Basic (June 2026)
- Threat Persistence: 0 days
- Ownership Changes: 0
- Status: No persistent malicious activity detected
---
RECOMMENDATIONS
No immediate firewall or blocking actions recommended. The IP address represents legitimate infrastructure for Ahrefs (SEO/marketing analytics platform). Monitor for:
- Unexpected behavioral changes
- Geolocation inconsistencies
- Emergence of open services or port scanning activity
SOC NOTE: This IP appears to be a legitimate proxy/firewalled endpoint within Ahrefs' infrastructure. The low risk score, lack of threat indicators, and corporate ownership support continued monitoring without aggressive blocking.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Ahrefs Pte Ltd administrator |
| ASN | AS140577 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | proxy-us002-san18.ahrefs.net |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | proxy-us002-san18.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 21% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 24% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 30% | 2 | 3 |
| Overall | 19% | 9 | 12 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:03:52 UTC |
| Last Seen | 2026-06-22 20:20:03 UTC |
| Profile Built | 2026-06-22 20:26:59 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 21 |
Full dossier details are available via our API.