# IP Intelligence Briefing: 198.244.168.192/32
## Executive Summary
IP address 198.244.168.192 was classified as a moderate risk endpoint (risk score: 50) with no direct threat indicators. The IP operates as a cloud-hosted proxy endpoint under OVH infrastructure in London, GB, associated with the ahrefs.net domain. Despite individual risk scoring, the subnet exhibits high abuse density (0.8438) with 216 of 256 sibling IPs flagged as threats.
## Network Profile
Ownership & Classification:
- ASN: 16276 (OVH)
- Organization: Ahrefs Pte Ltd Dmytro
- Location: London, England, GB
- Infrastructure Type: CloudCompute
- Network Role: Hosting provider with no active services
DNS Resolution:
- PTR Record: proxy-uk001-san192.ahrefs.net
- Forward Resolution: Confirmed to ahrefs.net domain
- Email Authentication: SPF and DMARC records absent
Control Plane:
- BGP Prefix: 198.244.128.0/17
- Route Stability: Unstable (changes detected)
- DNSBL Listings: 2 out of 8 total lists
- RPKI State: Not evaluated
- DNSSEC: Valid
## Threat Assessment
Direct Threat Indicators:
- Is Tor Exit: No
- Is Known Attacker: No
- Is Spam Source: No
- Is Proxy: No
- Active Threats: None detected
- Campaign Correlation: No matches
Subnet Context:
- Classification: high_abuse
- Abuse Density: 0.8438 (84.38%)
- Active Siblings: 208/256
- Threat Siblings: 216
- Inherited Risk Score: 33
## Historical Analysis
Observation history tracked 22 signal events. Recent probes (June 2026) maintained consistent cloud hosting classification under OVH. Geovalidation confirmed plausible London placement via multi-signal inference (5 probe points, average RTT: 93.8ms). No persistent malicious behavior observed over the observation period.
## Infrastructure Relationships
Relationship graph identified 43 connections, primarily same-network associations to OVH_282347337. No certificate, hostname, or organizational cross-links detected beyond network-level associations.
## Recommended Actions
Based on moderate risk classification and high-abuse subnet context, the following defensive controls are recommended:
Firewall Rules:
- iptables: `iptables -A INPUT -s 198.244.168.192 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 198.244.168.192 drop`
Application-Level Blocking:
- nginx: `deny 198.244.168.192;`
- pfSense: Block 198.244.168.192/32
- Cloudflare WAF: Block IP with expression `ip.src eq 198.244.168.192`
- AWS WAF: Add 198.244.168.192/32 to block list
## Intelligence Notes
The IP represents a legitimate cloud-hosted service endpoint (ahrefs.net) but operates within a high-abuse density subnet. While the endpoint itself shows no active malicious indicators, the subnet context warrants conservative blocking policies. SOC analysts should monitor for any behavioral changes from this IP, particularly given the unstable routing history and high sibling threat concentration.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk001-san192.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk001-san192.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 24% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-21 20:59:55 UTC |
| Last Seen | 2026-06-28 15:44:09 UTC |
| Profile Built | 2026-06-29 03:48:08 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 25 |
Full dossier details are available via our API.