IPDebrief

202.8.41.127

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING: 202.8.41.127/32

Classification: LOW RISK / INFRASTRUCTURE

Date: 2026-07-30

Analyst: IPDebrief Intelligence Team

---

## EXECUTIVE SUMMARY

IP 202.8.41.127 is classified as a low-risk infrastructure address belonging to Ahrefs Pte Ltd, a legitimate SEO analytics and web crawler infrastructure. The IP operates within the AHREFS-CRAWLER-A-USA network block and demonstrates consistent operational stability with no malicious indicators.

---

## OWNERSHIP & INFRASTRUCTURE

AttributeValue
**Organization**Ahrefs Pte Ltd administrator
**Netname**AHREFS-CRAWLER-A-USA
**ASN**140577
**CIDR Block**202.8.40.0/23
**RIR**APNIC
**Abuse Contact**Available via RDAP

The IP is registered under Ahrefs' crawler infrastructure program, consistent with legitimate web-scraping and SEO analytics operations.

---

## GEOSPATIAL DATA

FieldValue
**Country**Singapore (SG)
**Coordinates**1.35°N, 103.82°E
**Timezone**Asia/Singapore
**Accuracy Radius**30 km

---

## NETWORK CLASSIFICATION

The IP demonstrates characteristics consistent with legitimate infrastructure hosting rather than malicious infrastructure.

---

## THREAT INDICATORS

IndicatorStatus
**Risk Score**25 / 100
**Abuse Confidence Score**Not Available
**Blacklist Count**0
**Known Attacker**No
**Spam Source**No
**Known Campaigns**None
**Threat Feeds**None

No active threat indicators detected. The IP shows no association with known malicious campaigns or threat actor infrastructure.

---

## SERVICE & PORT ANALYSIS

PortProtocolServiceStatus
22TCPSSHOpen
*Banner*-SSH-2.0-OpenSSH_10.0p2 Debian-7+deb13u4Standard

SSH service detected with standard Debian OpenSSH build. No web services (HTTP/HTTPS) detected on common ports.

---

## DNS ANALYSIS

DNS records align with Ahrefs infrastructure naming conventions.

---

## NEIGHBORHOOD ANALYSIS

Subnet: 202.8.41.0/24

MetricValue
**Total Siblings**143
**Active Siblings**71
**Threat Siblings**11
**Abuse Density**0.0769 (7.69%)
**Classification**Mostly Clean
**Risk Distribution**0 High, 5 Medium, 95 Low

The /24 subnet demonstrates low abuse density with the vast majority of addresses classified as low-risk. This IP exists within a predominantly clean subnet environment.

---

## OBSERVATION HISTORY

Signal Count: 20 observations

Key temporal findings:

The IP demonstrates stable operational characteristics with no escalating threat patterns over time.

---

## RELATIONSHIP MAPPING

DNS Associations: sardine383.ahrefs.net (multiple records)

Network Associations: AHREFS-CRAWLER-A-USA

Correlated Entities: None identified

All relationship mappings align with legitimate Ahrefs infrastructure operations.

---

## RECOMMENDED ACTIONS

ActionRecommendation
**Firewall Rules**No specific rules required
**Traffic Analysis**Monitor for unusual outbound patterns
**Threat Intelligence**No action required
**ISP Notification**Not required
**Block Recommendation**Do not block

The IP presents no immediate threat requiring defensive action. Standard logging and monitoring practices are sufficient.

---

## CONCLUSION

IP 202.8.41.127 is a legitimate infrastructure address associated with Ahrefs' crawler operations. The address demonstrates:

1. Low Risk Profile: Risk score of 25 with no active threat indicators

2. Stable Operations: Consistent classification and no ownership changes

3. Clean Neighborhood: Exists within a predominantly low-risk subnet

4. Legitimate Infrastructure: Properly registered with APNIC and operational through Ahrefs

Recommendation: Allow traffic with standard monitoring. No blocking or alerting recommended.

---

*Report generated by IPDebrief Intelligence Platform. Data current as of 2026-07-30.*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΈπŸ‡¬ Singapore
RegionVA
CityAshburn
TimezoneAsia/Singapore
Latitude1.35
Longitude103.82

🏒 Ownership & Registration

OrganizationAhrefs Pte Ltd administrator
ASNAS140577
Network NameAHREFS-CRAWLER-A-USA
CIDR Block202.8.40.0/23
RIRAPNIC
CountryUS
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRsardine383.ahrefs.net
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamessardine383.ahrefs.net

πŸ” DNS Hygiene

Hygiene Score60% (Good)
SPFNot configured
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAAPresent

☁️ Network Classification

InfrastructureUnknown
Service PurposeSingle-Service Host
Network TierTier 3 β€” Basic operator with some routing infrastructure
No specific classification

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
22sshtcp
Closed Ports25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”
SSH VersionSSH-2.0-OpenSSH_10.0p2 Debian-7+deb13u4

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
0%
00
reputation
0%
00
geolocation
25%
11
Overall16%44
Coverage: 4/6 dimensions Β· Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-07-25 08:45:19 UTC
Last Seen2026-07-30 03:12:54 UTC
Profile Built2026-07-30 03:25:13 UTC
Data FreshnessLive
Signal Types21
Total Observations21
πŸ” 21 signal types Β· 21 observations collected
This report is generated from 21+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.