# IPDEBRIEF INTELLIGENCE BRIEFING
Target IP: 198.244.168.173/32
Classification: Moderate Risk
Date: 2026-06-14
---
## EXECUTIVE SUMMARY
IP 198.244.168.173 is a hosting infrastructure endpoint owned by Ahrefs Pte Ltd Dmytro, hosted on OVH UK infrastructure in London. The IP demonstrates moderate risk (score: 40) with no active threat indicators. While the subnet exhibits elevated abuse density, the specific IP shows no malicious activity and maintains legitimate service associations.
---
## OWNERSHIP & INFRASTRUCTURE
- ASN: 16276 (OVH)
- Organization: Ahrefs Pte Ltd Dmytro
- Geolocation: London, England, GB (750km accuracy radius)
- Network Block: 198.244.128.0/17
- Infrastructure Type: Hosting (Firewalled/No Services)
- Cloud/Proxy/VPN: Not detected
---
## DNS & RESOLUTION
- PTR Hostname: proxy-uk001-san173.ahrefs.net
- Forward Resolution: ahrefs.net domain
- Reverse Confirmation: Unverified
- DNSSEC Valid: Yes
- CAA Records: Present
- DNSBL Listed: 1 of 8 total lists
---
## THREAT ASSESSMENT
| Metric | Value |
|---|---|
| **Risk Score** | 40 (Moderate) |
| **Abuse Confidence** | Not applicable |
| **Blacklist Count** | 0 |
| **Tor Exit Node** | No |
| **Known Attacker** | No |
| **Spam Source** | No |
| **Campaign Matches** | 0 |
Threat Indicators: None detected. IP shows no evidence of malicious activity.
---
## NETWORK CONTEXT
Subnet Analysis (198.244.168.0/24):
- Abuse Density: 0.668 (High Abuse Classification)
- Inherited Risk Score: 26
- Active Siblings: 164 of 256
- Threat Siblings: 171
- Neighbor Risk Distribution: All neighbors show risk score 40
Observation: The subnet exhibits elevated abuse density typical of large hosting environments. However, the specific IP does not show malicious behavior despite the neighborhood context.
---
## TEMPORAL ANALYSIS
- Total Observations: 23
- Threat Persistence Days: 0
- Ownership Changes: 0
- Most Recent Signal: 2026-06-14T23:19:52+00:00
- Persistence Status: Not persistently malicious
---
## RECOMMENDED ACTIONS
SOC Analyst Actions:
1. Monitor but Do Not Block: IP represents legitimate Ahrefs infrastructure with no active threats
2. Allow Standard Traffic: No firewall rules recommended
3. Log Connection Activity: Monitor for anomalous patterns despite low-risk profile
4. Consider Subnet Context: Be aware of elevated abuse density in the /24 block
Firewall Rules: None required. IP demonstrates normal hosting behavior with appropriate DNS resolution to ahrefs.net infrastructure.
---
## INTELLIGENCE NOTES
The IP resolves to a proxy hostname within Ahrefs' UK infrastructure. While the broader subnet shows high abuse density (171 threat siblings), this specific endpoint maintains clean threat indicators. The single DNSBL listing appears to be a false positive or low-severity listing unrelated to active threats. Recommended approach: monitor, do not block.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk001-san173.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk001-san173.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 24% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-14 19:28:42 UTC |
| Last Seen | 2026-06-28 01:21:22 UTC |
| Profile Built | 2026-06-28 19:26:36 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 25 |
Full dossier details are available via our API.