## INTELLIGENCE BRIEFING: 168.100.149.79/32
Classification: Low Risk Infrastructure | Date: June 26, 2026
Analysis: SOC Intelligence Team
Executive Summary
IP 168.100.149.79 is a firewalled infrastructure node belonging to Ahrefs Pte Ltd (ASN 140577), registered in Virginia, USA. The IP carries a risk score of 25 and is classified as low risk. No active threat indicators were detected during the analysis window.
---
Ownership and Registration
- Organization: Ahrefs Pte Ltd administrator
- ASN: 140577
- Country: US (Virginia, Ashburn region)
- Network Role: Firewalled / No Services
- BGP Prefix: 168.144.0/20 (origin)
Technical Profile
- Risk Score: 25 (Low Risk)
- DNS Resolution: proxy-us001-san29.ahrefs.net (forward confirmed)
- Open Ports: None detected
- Service Status: No HTTP/HTTPS services exposed
- DNSBL Status: Listed on 1 of 8 threat feeds
Neighborhood Analysis (168.100.149.0/24)
- Total Subnet Size: 213 active siblings
- Risk Distribution: 0 high-risk, 18 medium-risk, 82 low-risk
- Abuse Density: 0.2817 (mixed classification)
- Threat Siblings: 60 IPs flagged within the /24
- Inherited Risk Score: 11
Historical Observations
- Total Signals: 22 observations tracked
- Recent Activity: June 26, 2026 (most recent)
- Threat Persistence: 0 days (not persistently malicious)
- Ownership Changes: 0
- Campaign Correlation: None detected
- Cert Matches: 0
Relationship Graph
- Network Associations: AHREFS-US (multiple links)
- DNS Associations: proxy-us001-san29.ahrefs.net (confirmed)
- Total Relationships: 34
- Campaign Correlated IPs: 0
---
Key Intelligence Indicators
β Low Risk Profile β Risk score 25, no active threat indicators
β Known Infrastructure β Ahrefs corporate network, established entity
β No Open Services β Firewalled configuration, no inbound services
β No Malicious Behavior β Zero threat observations, zero campaign matches
β οΈ RTT Anomaly β Geographic validation shows 27ms RTT vs. 126.2ms minimum possible distance, indicating potential multi-signal inference or routing anomaly
β οΈ Subnet Context β 60 threat siblings within /24 suggest elevated activity in broader subnet
---
Recommended Actions
- No immediate blocking required β IP classified as low risk with no active threat indicators
- Monitor subnet 168.100.149.0/24 β 60 threat siblings warrant network-level monitoring
- Validate geolocation β RTT anomaly suggests potential routing irregularity or data quality issue
- Log traffic patterns β Track connection frequency to establish baseline for this infrastructure node
---
Conclusion
168.100.149.79 represents legitimate Ahrefs infrastructure with no current malicious indicators. The IP should be permitted through security controls, with monitoring focused on the broader /24 subnet due to elevated sibling threat activity. No firewall rules or blocking actions recommended at this time.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Ahrefs Pte Ltd administrator |
| ASN | AS140577 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | proxy-us001-san29.ahrefs.net |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | proxy-us001-san29.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 19% | 10 | 14 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-10 22:17:18 UTC |
| Last Seen | 2026-06-26 04:27:30 UTC |
| Profile Built | 2026-06-26 04:35:00 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 23 |
Full dossier details are available via our API.