# IP INTELLIGENCE BRIEFING
Target IP: 198.244.168.200/32
Classification: Moderate Risk (Score: 40)
Date: 2026-06-23
---
## EXECUTIVE SUMMARY
IP 198.244.168.200 presents a moderate risk profile (40/100) associated with OVH cloud infrastructure in London, England. While the IP itself lacks direct malicious indicators, it operates within a high-abuse-density subnet (0.793 abuse density) with 203 sibling IPs flagged as threats. No active services are detected on the target IP; it functions as a firewalled infrastructure endpoint.
---
## OWNERSHIP AND INFRASTRUCTURE
| Attribute | Value |
|---|---|
| **ASN** | 16276 |
| **Organization** | Ahrefs Pte Ltd Dmytro |
| **Provider** | OVH (CloudCompute) |
| **Geolocation** | London, England, GB |
| **Network Class** | Cloud Hosting |
| **BGP Prefix** | 198.244.128.0/17 |
| **Route Stability** | Stable (no changes in 30 days) |
---
## THREAT ASSESSMENT
Direct Threat Indicators: None detected
- No Tor exit node activity
- No known campaign associations
- Zero blacklist listings
- No spam source classification
Subnet Context: CRITICAL
- Abuse Density: 0.793 (high_abuse classification)
- Active Siblings: 199/256 IPs
- Threat Siblings: 203 IPs flagged for abuse
- Neighborhood Risk Score: 31 (inherited)
---
## OBSERVATION HISTORY
Signal Count: 30 observations tracked
- Recent Activity: Signals observed on 2026-06-19 and 2026-06-23
- Geolocation Consistency: Validated at 473.7km distance from probe origin
- Operator Score: 0.6087 (Moderate confidence)
- Threat Persistence: Not persistently malicious (0 threat observation days)
---
## NETWORK BEHAVIOR
| Metric | Value |
|---|---|
| **Open Ports** | None detected |
| **TLS Certificate** | None |
| **HTTP Banner** | None |
| **PTR Hostname** | proxy-uk001-san200.ahrefs.net |
| **DNS Forward Confirmed** | No |
Note: Infrastructure appears firewalled with no publicly accessible services.
---
## RECOMMENDED ACTIONS
Blocking Recommended: Yes (based on subnet abuse density and moderate risk)
Firewall Rules
| System | Rule |
|---|---|
| **iptables** | `iptables -A INPUT -s 198.244.168.200 -j DROP` |
| **nftables** | `nft add rule inet filter input ip saddr 198.244.168.200 drop` |
| **nginx** | `deny 198.244.168.200;` |
| **pfSense** | `198.244.168.200/32` |
| **Cloudflare WAF** | Block IP with filter expression |
| **AWS WAF** | Add to blocked addresses list |
---
## ANALYST NOTES
1. Subnet Correlation: 79% of /24 subnet (198.244.168.0/24) shows abuse density. Consider blocking entire /24 if policy permits.
2. OVH Cloud Context: Infrastructure hosted on OVH in London. Multiple IPs in same network (OVH_282347337) show similar risk profiles.
3. False Positive Risk: While direct threat indicators are absent, the high-abuse neighborhood suggests potential for compromised infrastructure within the same hosting block.
4. Monitoring Recommendation: Track for any service emergence or threat indicator emergence within the 198.244.168.0/24 subnet.
---
Report Generated: IPDebrief Intelligence Platform
Classification: Threat Intelligence - Defensive Security Use Only
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | 198.244.128.0/17 |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk001-san200.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk001-san200.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 22% | 3 | 4 |
| services | 12% | 2 | 2 |
| ownership | 24% | 3 | 4 |
| reputation | 31% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 25% | 13 | 20 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (65%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:06 UTC |
| Last Seen | 2026-06-27 02:36:02 UTC |
| Profile Built | 2026-06-27 20:42:35 UTC |
| Data Freshness | Live |
| Signal Types | 28 |
| Total Observations | 34 |
Full dossier details are available via our API.