IPDebrief

92.222.108.125

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

IP Intelligence Briefing: 92.222.108.125

*Generated via IPDebrief Analysis*

---

**1. Core Profile**

- AS16276 (OVH)

- Organization: Ahrefs Pte Ltd (Singapore-based SEO tools provider)

- Country: France (FR)

- Region: Île-de-France (Paris)

- City: Domont (suburb of Paris)

- Provider: OVH CloudCompute

- Service Type: Hosting / Firewalled

- Infrastructure: Cloud-hosted (not residential or mobile)

---

**2. Threat & Behavior**

- Recent observation (June 8, 2026) labels it as a VPN proxy with a risk score of 66.

- DNS records associate it with proxy-fr002-san125.ahrefs.net (Ahrefs subdomain).

- No direct malware/C2 indicators detected.

- Subnet 92.222.108.125/24 shows high abuse density (67.74%), with 21 threat siblings (neighboring IPs flagged for risk).

---

**3. Network Context**

- Total IPs: 31 (24-bit subnet)

- Active IPs: 18

- Threat IPs: 21 (67.74% abuse density)

- Inherited Risk: 27 (moderate)

- Most IPs in the subnet have risk scores of 40–50, with some flagged for proxy activity.

---

**4. Observations & Trends**

- Consistent geolocation in Île-de-France since May 2026.

- Proxy classification emerged in June 2026, suggesting potential misuse.

- No open ports or TLS certificates detected.

- DNSSEC and CAA records are valid, but no email authentication (SPF/DKIM) found.

---

**5. Recommendations**

---

*Generated by IPDebrief. All data sourced from legitimate threat intelligence feeds.*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡«πŸ‡· France
RegionÎle-de-France
CityDomont
TimezoneEurope/Paris
Latitude48.86
Longitude2.35

🏒 Ownership & Registration

OrganizationAhrefs Pte Ltd Dmytro
ASNAS16276
Network Nameβ€”
CIDR Blockβ€”
RIRRIPE
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRproxy-fr002-san125.ahrefs.net
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesproxy-fr002-san125.ahrefs.net

πŸ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAAPresent

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting β€” Infrastructure provider without advanced routing
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
39%
23
routing
13%
11
services
15%
22
ownership
20%
23
reputation
22%
12
geolocation
25%
22
Overall22%1013
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-16 14:59:52 UTC
Last Seen2026-06-28 03:46:32 UTC
Profile Built2026-06-28 21:52:38 UTC
Data FreshnessLive
Signal Types20
Total Observations23
πŸ” 20 signal types Β· 23 observations collected
This report is generated from 20+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.