# IPDEBRIEF THREAT INTELLIGENCE BRIEFING
Target: 198.244.168.21/32
Classification: Moderate Risk | Date: Current
Analyst: Automated Intelligence System
---
## EXECUTIVE SUMMARY
IP 198.244.168.21 is a cloud-hosting endpoint operated by OVH (ASN 16276) with moderate risk profile (Risk Score: 40). The IP resolves to proxy-uk001-san21.ahrefs.net, indicating association with Ahrefs infrastructure in London, United Kingdom. The IP operates within a high-abuse density subnet (0.8242 abuse density) with 211 threat-sibling IPs out of 256 total addresses in the /24.
---
## OWNERSHIP & GEOGRAPHY
- Organization: Ahrefs Pte Ltd Dmytro
- Provider: OVH (ASN 16276, RIPE-NCC registry)
- Location: London, England, GB (confirmed via multi-signal inference)
- Infrastructure Type: CloudCompute / Hosting
- CIDR Block: 198.244.128.0/17
---
## NETWORK CHARACTERISTICS
- DNS Resolution: proxy-uk001-san21.ahrefs.net (ahrefs.net)
- Forward Resolution: Confirmed (1 hostname)
- Open Ports: None detected (Firewalled / No Services)
- TLS Certificate: None detected
- Network Status: Active but service-agnostic
---
## THREAT ASSESSMENT
- Overall Risk Score: 40 (Moderate)
- Abuse Confidence: Not explicitly scored
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0
- DNSBL Listed: 1 of 8 lists
- Threat Indicators: None detected
---
## NEIGHBORHOOD ANALYSIS
Subnet 198.244.168.0/24 classified as high_abuse:
- Abuse Density: 0.8242 (High)
- Total Siblings: 256
- Active Siblings: 199
- Threat Siblings: 211
- Risk Distribution: 100 medium-risk neighbors detected
- Inherited Risk: 32 (from neighborhood context)
This subnet demonstrates elevated abuse activity, though the target IP lacks direct threat indicators.
---
## OBSERVATION HISTORY
Total Observations: 29 signals across monitoring period
- Recent Activity: Consistent high_abuse classification observed
- Control Plane: Operator score 0.6087 (Moderate), route stability confirmed
- Geolocation Stability: Consistent GB/London placement
- Network RTT: 96-99ms average latency from probe location
- Persistence: Not persistently malicious (threatPersistenceDays: 0)
---
## RELATIONSHIP ANALYSIS
Detected Relationships: 42 total
- Primary Association: OVH network infrastructure (OVH_282347337)
- Network Classification: Same Network relationships indicate shared hosting environment
- No Campaign Correlations: Zero matched CERT events or correlated IPs
---
## RECOMMENDED ACTIONS
Despite no direct threat indicators, the subnet-level abuse density warrants defensive posture:
Immediate Firewall Rules
```bash
# iptables
iptables -A INPUT -s 198.244.168.21 -j DROP
# nftables
nft add rule inet filter input ip saddr 198.244.168.21 drop
# pfSense
198.244.168.21/32
```
WAF Configuration
- Cloudflare WAF: Block with expression `ip.src eq 198.244.168.21`
- AWS WAF: Add IP to blocked addresses list (198.244.168.21/32)
SOC Guidance
Action Priority: Medium
Rationale: Moderate risk score combined with high-abuse subnet density. While no active threat indicators are present, the neighborhood context suggests potential for abuse. Monitor for changes in reputation or emergence of threat indicators.
Additional Context: The IP hosts no services and is firewalled, reducing immediate attack surface. Association with Ahrefs infrastructure (legitimate SEO analytics company) provides some legitimacy, but the subnet abuse density warrants continued monitoring.
---
*Generated via IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | 198.244.128.0/17 |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk001-san21.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk001-san21.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 2 โ Moderate operator sophistication with routing hygiene |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 4 |
| routing | 22% | 3 | 4 |
| services | 12% | 2 | 2 |
| ownership | 24% | 3 | 4 |
| reputation | 28% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 24% | 13 | 20 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (65%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:06 UTC |
| Last Seen | 2026-06-27 02:36:22 UTC |
| Profile Built | 2026-06-27 20:42:35 UTC |
| Data Freshness | Live |
| Signal Types | 28 |
| Total Observations | 33 |
Full dossier details are available via our API.