IPDebrief

198.244.168.1

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING

Target: 198.244.168.1/32

Classification: Moderate Risk / Cloud Infrastructure

Date: Current

Source: IPDebrief Intelligence Platform

---

## EXECUTIVE SUMMARY

IP 198.244.168.1 is a cloud-compute instance hosted within OVH infrastructure, associated with the Ahrefs Pte Ltd organization. The IP presents a moderate risk profile (Score: 40) with no active threat indicators. However, the /24 subnet demonstrates elevated abuse density (0.7695), suggesting potential collateral risk from neighboring addresses. No direct malicious activity observed; the IP serves as a firewalled endpoint with no open services.

---

## OWNERSHIP & INFRASTRUCTURE

AttributeValue
**ASN**16276 (OVH)
**Organization**Ahrefs Pte Ltd Dmytro
**Infrastructure Type**CloudCompute
**Network Role**Hosting / Cloud Provider
**BGP Origin**198.244.128.0/17
**AS Path**57866 โ†’ 16276
**Route Stability**Stable (0 changes in 30 days)

Note: Control plane data indicates RPKI state and IRR consistency pending validation. Delegation age: 9,251 days.

---

## GEOLOCATION & DNS

AttributeValue
**Country**GB (England)
**City**London
**Timezone**Europe/London
**PTR Hostname**proxy-uk001-san1.ahrefs.net
**Domain**ahrefs.net
**Forward Resolution**Unconfirmed
**Geo Consensus**False (Inconsistent data sources)
**DNSSEC**Valid

Geographic Discrepancy: ASN registry indicates FR (France) allocation (2001-02-15), while geolocation data points to England. This inconsistency warrants monitoring.

---

## THREAT ANALYSIS

IndicatorStatus
**Risk Score**40 / 100 (Moderate)
**Abuse Confidence**Not Available
**Known Attacker**False
**Spam Source**False
**Tor Exit Node**False
**Blacklist Count**0
**DNSBL Listings**1 / 8 lists
**Campaign Correlation**None detected

Behavioral Status: No persistent malicious activity. Threat observation count: 1. Stability score: 0.

---

## NEIGHBORHOOD CONTEXT

MetricValue
**Subnet**198.244.168.0/24
**Total Siblings**256
**Active Siblings**191
**Threat Siblings**197
**Abuse Density**0.7695 (High)
**Classification**High Abuse
**Inherited Risk**30

Critical Finding: The /24 subnet shows significant abuse density with 197 of 256 total IPs flagged as threats. This elevated neighborhood risk suggests compromised infrastructure sharing. Neighboring IPs (198.244.168.0-5) all show risk scores of 40 with authority scores of 50.

---

## SERVICES & NETWORK ROLE

AttributeValue
**Open Ports**None detected
**Service Purpose**Firewalled / No Services
**TLS Certificate**None
**HTTP Banner**None
**CDN**False
**Proxy**False
**Mobile**False
**Residential**False

Analysis: The target IP appears to be a backend or management endpoint with no exposed services. This is consistent with cloud infrastructure hosting.

---

## OBSERVATION HISTORY

Total Observations: 23

Recent Activity: June 2026

Key Historical Signals:

Temporal Assessment: The IP demonstrates stable network behavior over the observation period. No escalation in risk profile observed.

---

## RELATIONSHIP GRAPH

Relationship TypeTargetCount
**Same Network**OVH_282347337Multiple

| DNS Association | proxy-uk

**Same Network**OVH_282347337Multiple
**DNS Association**proxy-uk001-san1.ahrefs.net16

---

## ACTIONABLE RECOMMENDATIONS

Immediate Actions

1. Block at Edge: Apply firewall rules for traffic from 198.244.168.1/32. Recommended ruleset:

- iptables: `iptables -A INPUT -s 198.244.168.1 -j DROP`

- nftables: `nft add rule inet filter input ip saddr 198.244.168.1 drop`

- Cloudflare WAF: Block with expression `ip.src eq 198.244.168.1`

2. Monitor Neighbors: Track adjacent IPs in 198.244.168.0/24 range. High abuse density (0.7695) indicates potential lateral threat vectors.

3. Validate DNS Records: Forward resolution unconfirmed for proxy-uk001-san1.ahrefs.net. Investigate DNS propagation status.

Long-Term Considerations

---

## RISK ASSESSMENT SUMMARY

CategoryRating
**Direct Threat**Low
**Infrastructure Risk**Moderate
**Neighborhood Risk**High
**Action Priority**Medium

Assessment Rationale: The target IP itself shows no active malicious indicators. However, the high-abuse neighborhood classification and 197 threat-siblings create contextual risk that warrants defensive posture. Recommend blocking while continuing surveillance for neighborhood correlation.

---

END OF BRIEFING

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฌ๐Ÿ‡ง United Kingdom
RegionEngland
CityLondon
TimezoneEurope/London
Latitude51.50
Longitude-0.12

๐Ÿข Ownership & Registration

OrganizationAhrefs Pte Ltd Dmytro
ASNAS16276
Network Nameโ€”
CIDR Block198.244.128.0/17
RIRARIN
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRproxy-uk001-san1.ahrefs.net
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesproxy-uk001-san1.ahrefs.net

๐Ÿ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAAPresent

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierTier 3 โ€” Basic operator with some routing infrastructure
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
33%
23
routing
33%
23
services
8%
11
ownership
37%
36
reputation
31%
13
geolocation
35%
23
Overall29%1119
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-19 23:49:32 UTC
Last Seen2026-06-28 10:27:49 UTC
Profile Built2026-06-29 04:32:51 UTC
Data FreshnessLive
Signal Types23
Total Observations29
๐Ÿ” 23 signal types ยท 29 observations collected
This report is generated from 23+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.