IP Intelligence Briefing: 176.31.139.6/32
Date: 2026-06-10
---
**1. IP Profile**
- Risk Score: 40 (Moderate Risk)
- Provider: OVH (CloudCompute infrastructure)
- Ownership: Ahrefs Pte Ltd Dmytro (ASN 16276)
- Geolocation: France (Roubaix), inferred with 0.52 confidence.
- Threat Indicators: No active malicious indicators, blacklists, or campaigns.
- Network Role: Cloud-hosted server (OVH), no residential/mobile/mobile carrier.
---
**2. Observation History**
- Recent Activity (June 2026):
- Listed in 2 high-risk threat feeds (confidence 0.85).
- Classified as CloudCompute infrastructure (OVH).
- Subnet 176.31.139.6/24 flagged as high_abuse with 65.62% abuse density.
- Geolocation inferred as France (Roubaix), but accuracy is low (500km radius).
---
**3. Relationships**
- DNS Associations: Linked to `proxy-fr004-san6.ahrefs.net` (Ahrefs).
- Network Connections:
- Part of OVH network (ASN 16276).
- Subnet 176.31.139.6/24 with 31 sibling IPs (21 flagged as high-risk).
- Threat Context: Subnet has 21 high-risk neighbors, suggesting potential for lateral movement or shared infrastructure risks.
---
**4. Neighborhood Analysis**
- Subnet: 176.31.139.6/24
- Abuse Density: 65.62% (high_abuse classification).
- Neighbor Risk Distribution:
- 31 IPs in subnet (21 high-risk, 10 medium-risk).
- 2 active IPs, 21 threat siblings.
- Recommendation: Monitor subnet for suspicious activity; consider blocking traffic from this subnet if not required.
---
**5. Actionable Insights**
- SOC Prioritization:
- Investigate subnet 176.31.139.0/24 for potential lateral movement or shared malicious infrastructure.
- Validate Ahrefs' use of this IP (legitimate proxy service or compromised host?).
- Firewall Rules:
- Block or restrict traffic from 176.31.139.0/24 unless explicitly allowed.
- Monitor DNS queries to `proxy-fr004-san6.ahrefs.net` for anomalies.
- Threat Hunt:
- Correlate with other IPs in the subnet for potential campaign ties.
---
Conclusion: This IP is part of a high-risk subnet managed by OVH, linked to Ahrefs. While the IP itself shows no direct malicious activity, the subnetβs abuse density and high-risk neighbors warrant close monitoring. Prioritize isolating or restricting access to this subnet to mitigate potential threats.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | β |
| CIDR Block | β |
| RIR | RIPE |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | proxy-fr004-san6.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-fr004-san6.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 46% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 23% | 1 | 2 |
| geolocation | 34% | 2 | 3 |
| Overall | 25% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-23 06:21:27 UTC |
| Last Seen | 2026-06-28 20:31:30 UTC |
| Profile Built | 2026-06-29 02:35:09 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.