IPDebrief

198.244.168.71

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IPDEBRIEF INTELLIGENCE BRIEFING

Target IP: 198.244.168.71/32

Date: 2026-06-20

Classification: MODERATE RISK โ€” Cloud Infrastructure Host

---

## EXECUTIVE SUMMARY

IP 198.244.168.71 is a cloud-hosted address in the OVH infrastructure (ASN 16276) located in London, England. The IP presents a moderate risk profile (score: 50) with elevated neighborhood-level abuse density and multiple DNS blacklist associations. No active threat campaigns or known attacker indicators were identified.

---

## OWNERSHIP AND INFRASTRUCTURE

AttributeValue
**ASN**16276
**Organization**Ahrefs Pte Ltd Dmytro
**Provider**OVH
**Infrastructure Type**CloudCompute
**Geolocation**London, England, GB
**CIDR Block**198.244.128.0/17
**Network Role**Host (Firewalled / No Services)

The IP resolves to forward hostname `proxy-uk001-san71.ahrefs.net` under domain `ahrefs.net`. No open ports or active services were detected. TLS certificates are not in use.

---

## THREAT INDICATORS

IndicatorStatus
**Risk Score**50 (Moderate)
**Abuse Confidence**Listed on 2 of 8 DNS blacklists
**Tor Exit Node**No
**Known Attacker**No
**Spam Source**No
**Campaign Matches**0
**Correlated IPs**0

The IP is listed on 2 DNS blacklist feeds with maximum severity rating of "high." No known malicious campaigns or threat feed indicators were associated with this address.

---

## NEIGHBORHOOD ANALYSIS

The IP resides within the 198.244.168.0/24 subnet, which demonstrates significantly elevated abuse characteristics:

MetricValue
**Abuse Density**0.8398 (High)
**Subnet Classification**high_abuse
**Total Siblings**256
**Active Siblings**208
**Threat Siblings**215
**Inherited Risk**33

The subnet contains 215 threat-sibling IPs among 208 active addresses, indicating systemic abuse patterns within this address block. Risk inheritance from neighborhood context is moderate (33).

---

## OBSERVATION HISTORY

Analysis of 19 signal observations reveals consistent patterns:

The IP has demonstrated temporal stability with no ownership changes observed.

---

## RELATIONSHIP GRAPH

The relationship analysis identified 42 associated entities, predominantly:

No additional organizational or certificate relationships were documented.

---

## RECOMMENDED ACTIONS

Based on risk profile analysis, the following firewall and mitigation rules are recommended:

PlatformRule
**iptables**`iptables -A INPUT -s 198.244.168.71 -j DROP`
**nftables**`nft add rule inet filter input ip saddr 198.244.168.71 drop`
**nginx**`deny 198.244.168.71;`
**pfSense**`198.244.168.71/32`
**Cloudflare WAF**Block IP 198.244.168.71 (risk score 50)
**AWS WAF**Add 198.244.168.71/32 to block list

---

## ANALYST NOTES

This IP operates within a high-abuse subnet environment but lacks direct malicious indicators. The moderate risk score (50) combined with DNS blacklist associations suggests potential for abuse or association with compromised infrastructure. Given the high-abuse neighborhood context (0.8398 abuse density), consider implementing subnet-level monitoring or blocking the broader 198.244.168.0/24 range if threat correlation is observed.

Recommendation: Monitor for activity patterns; consider blocking based on operational requirements and threat correlation with other indicators.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฌ๐Ÿ‡ง United Kingdom
RegionEngland
CityLondon
TimezoneEurope/London
Latitude51.50
Longitude-0.12

๐Ÿข Ownership & Registration

OrganizationAhrefs Pte Ltd Dmytro
ASNAS16276
Network Nameโ€”
CIDR Blockโ€”
RIRARIN
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRproxy-uk001-san71.ahrefs.net
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesproxy-uk001-san71.ahrefs.net

๐Ÿ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAAPresent

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
33%
22
routing
13%
11
services
8%
11
ownership
20%
23
reputation
23%
12
geolocation
34%
23
Overall22%912
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-24 00:31:56 UTC
Last Seen2026-06-28 23:18:55 UTC
Profile Built2026-06-29 05:20:02 UTC
Data FreshnessLive
Signal Types19
Total Observations21
๐Ÿ” 19 signal types ยท 21 observations collected
This report is generated from 19+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.