# IP Intelligence Briefing: 37.59.204.143/32
## Executive Summary
IP 37.59.204.143 presents as a cloud-hosted infrastructure endpoint associated with Ahrefs Pte Ltd Dmytro (ASN 16276, OVH provider). The IP carries a moderate risk score of 40 and is classified as "high_abuse" within its subnet. While the endpoint itself shows no active threat indicators, the surrounding neighborhood exhibits significant abuse density (0.7188), suggesting potential infrastructure sharing with malicious actors.
## Infrastructure Profile
- IP Address: 37.59.204.143/32
- Provider: OVH (ASN 16276)
- Organization: Ahrefs Pte Ltd Dmytro
- Country: France (FR)
- Infrastructure Type: CloudCompute
- DNS Resolution: proxy-fr007-san143.ahrefs.net
- Network Classification: Cloud hosting infrastructure, no active services detected
## Risk Assessment
- Overall Risk Score: 40 (Moderate Risk)
- Abuse Confidence Score: Not available
- Blacklist Count: 0
- DNSBL Listings: 1 out of 8 total lists
- Operator Score: 0.2174 (Minimal)
- Threat Indicators: None currently detected
- Known Campaigns: None identified
The IP resolves to an Ahrefs-owned proxy hostname but operates within a high-abuse-density subnet. This mismatch between legitimate domain ownership and neighborhood risk profile warrants monitoring.
## Neighborhood Analysis (37.59.204.0/24)
- Total Siblings: 32 IPs
- Active Siblings: 12
- Threat Siblings: 23
- Abuse Density: 0.7188 (High)
- Risk Distribution: 28 medium-risk, 3 low-risk, 0 high-risk neighbors
The subnet demonstrates elevated abuse characteristics. The IP shares a network segment with 23 threat-siblings, indicating potential infrastructure co-location with known malicious actors.
## Observation History
Analysis of 23 historical observations reveals:
- Recent operator score assessments indicate "Minimal" risk classification
- One high-severity DNSBL listing detected on 2026-06-23
- Geolocation data validated with 97ms average RTT from France
- No persistent malicious behavior observed (threat persistence days: 0)
- Route stability flagged as false despite zero BGP changes in 30 days
## Network Relationships
The IP maintains connections within the OVH_282114232 network relationship cluster. Multiple same-network associations indicate broader infrastructure relationships within the OVH provider ecosystem.
## Recommended Actions
1. Monitor traffic patterns between 37.59.204.143 and adjacent threat-sibling IPs in the /24 subnet
2. Review firewall rules for this subnet given the 0.7188 abuse density
3. Correlate with Ahrefs infrastructure baseline to confirm legitimate vs. compromised usage
4. Track DNSBL listing changes and assess impact on reputation services
5. Evaluate whether cloud hosting classification masks malicious backend infrastructure
## Conclusion
IP 37.59.204.143 currently operates as legitimate cloud infrastructure without active threat indicators. However, the high-abuse-density environment and proximity to 23 threat-siblings suggest potential for infrastructure sharing with malicious entities. SOC teams should monitor for anomalous outbound connections and cross-reference with known Ahrefs security baselines.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-fr007-san143.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-fr007-san143.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 32% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 22% | 9 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:18 UTC |
| Last Seen | 2026-06-27 05:06:57 UTC |
| Profile Built | 2026-06-27 23:13:25 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 25 |
Full dossier details are available via our API.