IP Intelligence Briefing: 198.244.168.31
*Generated via IPDebrief Tools*
---
**1. Core Profile**
- Risk Score: 25 (Low Risk)
- Ownership: Ahrefs Pte Ltd (AS16276, OVH provider)
- Geolocation: London, England (GB), inferred via DNS and routing data.
- Network Role: CloudCompute infrastructure (OVH-hosted, no CDN/VPN/Proxy).
- Threat Indicators: No malicious activity detected (no blacklists, spam, or campaign ties).
- Services: No open ports or TLS certificates observed.
---
**2. Observation History (Last 30 Days)**
- Stable low-risk profile with no significant changes.
- Consistent geolocation and ownership data.
- No spikes in threat signals or abnormal network behavior.
---
**3. Relationships**
- Linked Entities:
- OVH Network (AS16276, subnet 198.244.128.0/17).
- DNS Hostname: `proxy-uk001-san31.ahrefs.net` (Ahrefs Pte Ltd).
- No malicious associations detected.
---
**4. Subnet Neighbors (/24: 198.244.168.0/24)**
- Abuse Density: 0.2024 (20.24% of subnet IPs flagged as risky).
- Key Neighbors:
- 100+ IPs in the subnet, with 55 medium-risk and 45 low-risk entries.
- Notable high-risk IPs: 5 (e.g., 198.244.168.2, 198.244.168.3).
- Recommendation: Monitor subnet for potential lateral movement or shared infrastructure risks.
---
**5. Actionable Insights**
- Traffic Allowance: Legitimate cloud infrastructure; no blocking required.
- Monitoring: Track subnet neighbors for anomalies, especially high-risk IPs.
- Verification: Confirm Ahrefsβ ownership via RDAP and validate DNS records.
---
Conclusion:
198.244.168.31 is a low-risk IP associated with Ahrefs Pte Ltdβs cloud infrastructure. No malicious activity detected, but the subnet has a moderate abuse density. SOC teams should focus on monitoring neighboring IPs for potential indirect risks.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | proxy-uk001-san31.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk001-san31.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 26% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-18 09:24:09 UTC |
| Last Seen | 2026-06-28 06:56:22 UTC |
| Profile Built | 2026-06-29 01:01:25 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 25 |
Full dossier details are available via our API.