IP Intelligence Briefing: 198.244.168.56
Date: 2026-06-10
---
**1. Core Profile**
- Risk Score: 25 (Low Risk)
- Ownership: Registered to Ahrefs Pte Ltd Dmytro (ASN 16276, OVH provider).
- Geolocation: London, England, UK (plausible via DNS geolocation).
- Network Role: CloudCompute instance under OVH, no CDN/proxy/VPN indicators.
- Threat Indicators: No malicious activity detected (no blacklists, spam, or known attacker associations).
---
**2. Observation History**
- Last 30 Days: Consistent low-risk signals (minimal abuse confidence, stable routing).
- Key Metrics:
- 1 threat observation (DNSSEC valid, CAA records present).
- No persistent malicious behavior or campaign correlations.
---
**3. Network Relationships**
- Linked Entities:
- OVH ASN 16276 (cloud infrastructure).
- Ahrefs.net (DNS hostname: `proxy-uk001-san56.ahrefs.net`).
- Subnet Context: Part of `198.244.128.0/17`, shared with 256 IPs (121 active, 125 flagged for abuse).
---
**4. Neighborhood Analysis**
- Subnet Abuse Density: 48.83% (mixed risk environment).
- Neighbor Risk: 73% low-risk, 27% medium-risk IPs.
- Notable Neighbors:
- 198.244.168.0/32 (risk score 40),
- 198.244.168.4/32 (risk score 50).
---
**5. Security Recommendations**
- No Immediate Actions Required: IP is associated with a legitimate entity (Ahrefs) and shows no malicious indicators.
- Monitor Subnet: Watch for unusual activity in the `198.244.168.0/24` subnet due to mixed abuse density.
- Verify DNS: Confirm `proxy-uk001-san56.ahrefs.net` is legitimate, as it is linked to the IP.
---
Conclusion:
198.244.168.56 is a low-risk cloud compute instance operated by Ahrefs, with no signs of malicious activity. While the broader subnet contains some risky neighbors, this IP itself is not a threat. SOC teams should focus on monitoring the subnet for anomalies but do not need to block or investigate this IP further.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk001-san56.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk001-san56.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 38% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 25% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-22 09:12:27 UTC |
| Last Seen | 2026-06-28 18:24:43 UTC |
| Profile Built | 2026-06-29 06:28:33 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 24 |
Full dossier details are available via our API.