# IP Intelligence Briefing: 198.244.168.228/32
## Executive Summary
IP address 198.244.168.228 was classified as Moderate Risk (risk score: 40) during analysis. The IP resides within the OVH cloud infrastructure (ASN 16276) in London, United Kingdom, and is associated with the Ahrefs Pte Ltd organization. The IP exhibits cloud hosting characteristics with firewalled services and no publicly accessible open ports.
## Infrastructure and Geolocation
The IP was geolocated to London, England (GB) with an accuracy radius of 750 km. Infrastructure classification identified the IP as cloud-based computing infrastructure under OVH provider. The control plane analysis showed the IP as part of BGP prefix 198.244.128.0/17 with route stability flags indicating instability over the measurement period. DNS resolution returned proxy-uk001-san228.ahrefs.net with no forward confirmation.
## Threat Indicators and Reputation
Threat indicators showed no classification as known attacker, spam source, or Tor exit node. The IP was listed on 1 out of 8 DNSBL lists. No known campaigns were correlated with this address. The control plane operator score was 0.2174 with an "Minimal" operator label.
## Subnet Analysis
The /24 neighborhood (198.244.168.0/24) demonstrated high abuse density at 0.75. Analysis of 256 total siblings showed 164 active siblings with 192 classified as threat siblings. Risk distribution across the subnet showed 64 medium-risk addresses and 36 low-risk addresses.
## Historical Observations
Observation history recorded 21 signal observations spanning from June 15 through June 28. The subnet's abuse density fluctuated between 0.4609 and 0.75 across the observation period. Classification varied between "mixed" and "high_abuse" designations. Provider identification consistently returned OVH for the 198.244.128.0/17 block.
## Recommended Actions
Based on the risk profile, the following defensive measures were recommended:
Firewall Rules:
- iptables: `iptables -A INPUT -s 198.244.168.228 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 198.244.168.228 drop`
- nginx: `deny 198.244.168.228;`
Cloud Platform Recommendations:
- pfSense: `198.244.168.228/32`
- Cloudflare WAF: Block with filter expression `ip.src eq 198.244.168.228`
- AWS WAF: Address block `198.244.168.228/32`
## Intelligence Assessment
The IP represents moderate-risk cloud infrastructure within a high-abuse subnet. While no direct malicious indicators were present, the subnet's elevated abuse density and the IP's DNSBL presence warrant monitoring. The recommendations above provide actionable blocking rules for deployment across defensive infrastructure.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk001-san228.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk001-san228.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 24% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-18 03:22:27 UTC |
| Last Seen | 2026-06-28 06:05:54 UTC |
| Profile Built | 2026-06-29 00:10:44 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 25 |
Full dossier details are available via our API.