# IP Intelligence Briefing: 198.244.168.179/32
Classification: Cloud Infrastructure Host with Moderate Risk Profile
---
## Executive Summary
IP 198.244.168.179 is a cloud computing infrastructure address operated by OVH (AS16276) in London, England. The IP demonstrates moderate risk characteristics with a risk score of 40 and is associated with the hosting provider OVH. No open services or active ports were detected during scanning. The IP is associated with the ahrefs.net domain through DNS records.
---
## Technical Profile
Infrastructure Classification:
- ASN: 16276 (OVH SAS)
- Location: GB-England-London
- Infrastructure Type: CloudCompute / Hosting
- Connection Type: Firewalled / No Services Detected
DNS Configuration:
- PTR Hostname: proxy-uk001-san179.ahrefs.net
- Forward Resolution: proxy-uk001-san179.ahrefs.net
- Domain: ahrefs.net
- Forward Resolution Count: 1
Network Routing:
- BGP Prefix: 198.244.128.0/17
- AS Path: 34549 16276
- Origin ASN: 16276
- Route Stability: Stable (no changes in 30 days)
- DNSSEC: Valid
- RIR Registry: RIPE NCC
---
## Risk Indicators
Current Risk Score: 40 (Moderate Risk)
Threat Indicators:
- Blacklist Status: Listed on 1 of 8 DNSBLs
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Abuse Confidence Score: Not available
Control Plane Data:
- Operator Score: 0.4348 (Basic)
- Delegation Age: 9,251 days
- Route Stability: True
---
## Neighborhood Analysis
Subnet: 198.244.168.179/24
- Abuse Density: 0.8203 (High Abuse Classification)
- Inherited Risk Score: 32
- Total Siblings: 256
- Active Siblings: 204
- Threat Siblings: 210
Neighbor Risk Distribution:
- High Risk: 0%
- Medium Risk: 49%
- Low Risk: 51%
The subnet shows elevated abuse density with 210 threat siblings out of 204 active addresses. This indicates a hosting environment with mixed legitimate and potentially compromised resources.
---
## Observation History
Total Observations: 24 signals observed
Key Historical Observations:
- ASN 16276 (OVH) consistently identified across multiple probes
- Geolocation inconsistencies noted: France (FR) and United Kingdom (GB) reported in different observation periods
- BGP routing confirmed for prefix 198.244.128.0/17
- RTT measurements indicate plausible latency (avg: 88.4ms, min: 9.5ms)
Threat Persistence:
- Threat Observation Count: 0
- Is Persistently Malicious: No
- Ownership Changes: 0
---
## Related Entities
Network Relationships:
- Multiple associations with OVH network OVH_282347337
- 40 total relationship entities identified
---
## Recommended Actions
Firewall/Routing Recommendations:
- No specific firewall rules generated based on current risk profile
- Monitor for changes in threat indicators
- Consider blocking if outbound connections from trusted sources to this IP are observed
Monitoring Priorities:
- Watch for service enumeration (currently no open ports detected)
- Monitor DNSBL listing status
- Track geolocation consistency
SOC Analyst Notes:
This IP represents cloud infrastructure hosting services. While currently classified as moderate risk with no active threat indicators, the high-abuse neighborhood context warrants periodic re-evaluation. No immediate blocking actions are recommended based on current data, but maintain visibility on this address in threat monitoring systems.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | 198.244.128.0/17 |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk001-san179.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk001-san179.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 2 |
| routing | 33% | 2 | 3 |
| services | 8% | 1 | 1 |
| ownership | 35% | 3 | 6 |
| reputation | 22% | 1 | 2 |
| geolocation | 30% | 2 | 3 |
| Overall | 25% | 11 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-19 23:49:33 UTC |
| Last Seen | 2026-06-28 10:29:08 UTC |
| Profile Built | 2026-06-29 04:34:01 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 30 |
Full dossier details are available via our API.