IP INTELLIGENCE BRIEFING: 198.244.168.229/32
Executive Summary
IP 198.244.168.229 is a moderate-risk (score: 40/100) cloud infrastructure address operated by OVH (ASN 16276) in London, England. While the individual IP shows no direct threat indicators, it resides within a high-abuse-density subnet (198.244.168.0/24) with 197 of 256 active sibling IPs flagged as threats. The IP is associated with Ahrefs Pte Ltd Dmytro and resolves to proxy-uk001-san229.ahrefs.net. No open services were detected; the host is currently firewalled.
Infrastructure Details
- ASN/Provider: OVH (16276), ARIN registry
- Geolocation: London, England, GB (validated, RTT: 89ms avg)
- Network Role: CloudCompute infrastructure (OVH)
- DNS: proxy-uk001-san229.ahrefs.net (forward resolution confirmed)
- Services: No open ports detected; host is firewalled
- Threat Indicators: None observed (0 blacklist hits, no Tor exit, no known campaigns)
Risk Context
The IP's risk profile is elevated by neighborhood characteristics rather than intrinsic malicious activity. The /24 subnet (198.244.168.0/24) exhibits high abuse density (0.7695) with 197 threat siblings out of 191 active addresses. All neighboring IPs in the neighborhood returned a risk score of 40. This suggests coordinated abuse or misconfiguration within the infrastructure block.
Historical Observations
Twenty-three signals recorded since last analysis. Operator score remains stable at 0.2174 (Minimal). Geolocation validation confirms plausible location in London with 473.7km distance from origin. No ownership changes or persistent malicious behavior detected.
Recommended Actions
- Block at perimeter: iptables, nftables, or firewall (pfsense) rule: `198.244.168.229/32`
- WAF Integration: Cloudflare WAF and AWS WAF block rules generated for IP
- Monitoring: Monitor for port scan activity or service exposure, as current state shows no open services
Assessment
This IP warrants blocking due to high neighborhood abuse density, though it does not exhibit direct malicious characteristics. The moderate risk score reflects proximity to compromised infrastructure rather than confirmed attacker behavior. SOC analysts should monitor for any service exposure changes or correlation with known threat campaigns.
Confidence Level: Moderate (neighborhood signals primary indicator)
Last Updated: 2026-06-20
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk001-san229.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk001-san229.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 24% | 9 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-20 11:46:13 UTC |
| Last Seen | 2026-06-28 11:39:06 UTC |
| Profile Built | 2026-06-29 05:42:43 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 24 |
Full dossier details are available via our API.