# IP Intelligence Briefing: 37.59.204.142
## Executive Summary
IP 37.59.204.142 is classified as Moderate Risk with a risk score of 50. The address is hosted on OVH infrastructure in France under Ahrefs Pte Ltd Dmytro (ASN 16276). The subnet exhibits high abuse density (0.7188) with 23 out of 32 siblings flagged as threats, though the target IP itself shows no active threat indicators.
## Profile Assessment
- Risk Score: 50 (Moderate Risk)
- Organization: Ahrefs Pte Ltd Dmytro (ASN: 16276)
- Location: France (FR), Europe/Paris timezone
- Provider: OVH (CloudCompute infrastructure)
- Network Classification: Cloud hosting environment, firewalled with no open services
- DNS Resolution: proxy-fr007-san142.ahrefs.net (ahrefs.net domain)
- Control Plane: Listed on 2 DNS blacklists out of 8 total checks
- Operator Score: 0.2174 (Minimal)
## Threat Indicators
No active threat indicators detected for this IP:
- Not a known attacker or Tor exit node
- No spam source classification
- Zero threat feeds matches
- No known campaign associations
- No certificate matches or correlated IPs
## Neighborhood Analysis
The /24 subnet (37.59.204.0/24) shows concerning abuse patterns:
- Abuse Density: 0.7188 (high_abuse classification)
- Total Siblings: 32
- Active Siblings: 13
- Threat Siblings: 23
- Inherited Risk: 28
Neighbor risk distribution is mixed, with risk scores ranging from 25-50. Notable neighbors include 37.59.204.128 (risk: 40) and 37.59.204.129 (risk: 50).
## Historical Context
Analysis of 23 observations reveals:
- Recent operator score observations indicate minimal risk (0.1 raw score on 2026-06-28)
- Historical subnet classification shows high_abuse designation observed on 2026-06-20
- Multiple ownership and geolocation signal observations over time
- No persistent malicious behavior flagged
## Recommended Actions
Based on the moderate risk profile and high-density neighborhood:
1. Monitor the subnet for lateral threat activity
2. Implement rate limiting if traffic originates from this range
3. Consider geo-blocking if traffic is unexpected for your operations
4. Review DNSBL listings for potential reputation impact
## Conclusion
This IP represents legitimate cloud hosting infrastructure with moderate risk characteristics. While the subnet shows elevated abuse density, the target IP itself lacks active threat indicators. The connection to ahrefs.net suggests legitimate business operations, but monitoring is recommended given the neighborhood's threat profile.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-fr007-san142.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-fr007-san142.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 26% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-19 21:40:12 UTC |
| Last Seen | 2026-06-28 10:06:07 UTC |
| Profile Built | 2026-06-29 04:10:01 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 25 |
Full dossier details are available via our API.