# IP Intelligence Briefing: 198.244.168.98/32
## Executive Summary
IP 198.244.168.98 is classified as Moderate Risk (risk score: 50) with a reputation profile indicating mixed threat characteristics. The address is hosted on OVH infrastructure in London, England (GB), and resolves to a Ahrefs-owned proxy hostname. While currently not flagged as a known attacker or spam source, the IP operates within a high-abuse density subnet environment.
## Profile Overview
| Attribute | Value |
|---|---|
| Risk Score | 50 (Moderate Risk) |
| ASN | 16276 |
| Organization | Ahrefs Pte Ltd Dmytro |
| Provider | OVH |
| Country | GB (England, London) |
| Infrastructure Type | CloudCompute |
| Network Classification | Hosting / Cloud |
## Technical Indicators
- DNS Resolution: proxy-uk001-san98.ahrefs.net (ahrefs.net domain)
- BGP Prefix: 198.244.128.0/17
- Origin ASN: 16276
- Route Stability: False (route changes detected within 30-day window)
- Service Status: Firewalled / No Services detected
- Open Ports: None identified
- TLS Certificates: None detected
## Threat Assessment
- Abuse Confidence: Not currently flagged as known attacker, spam source, or Tor exit node
- Blacklist Status: 2 DNSBL listings out of 8 total lists
- Campaign Correlation: No known campaign matches
- Threat Persistence: 0 threat persistence days (not persistently malicious)
- Control Plane Status: 0 route changes in 30 days, isRouteStable: false
## Neighborhood Analysis
The IP resides in subnet 198.244.168.0/24, characterized by:
- Abuse Density: 0.8203 (high abuse classification)
- Total Siblings: 256
- Active Siblings: 204
- Threat Siblings: 210
- Inherited Risk: 32
Risk Distribution in Subnet: 52 medium-risk, 48 low-risk, 0 high-risk IPs sampled.
## Historical Trends (22 Observations)
- June 20, 2026: Abuse density 0.8203, classification "high_abuse", inherited risk 32, threat siblings 210
- June 28, 2026: Abuse density decreased to 0.4609, classification shifted to "mixed", inherited risk 18, threat siblings 118
- Provider Detection: OVH hosting classification confirmed June 20, 2026
- Geolocation: Inferred GB with 750km accuracy radius
## Network Relationships
- 38 Relationships Detected: Multiple connections to network OVH_282347337
- Same Provider/Network: Confirmed OVH infrastructure association
## Recommended Actions
Based on risk profile and neighborhood context, the following firewall rules are recommended:
iptables: `iptables -A INPUT -s 198.244.168.98 -j DROP`
nftables: `nft add rule inet filter input ip saddr 198.244.168.98 drop`
nginx: `deny 198.244.168.98;`
Cloudflare WAF: Block with expression `ip.src eq 198.244.168.98`
AWS WAF: Add rule for address 198.244.168.98/32 with description "IPDebrief risk 50"
## Analyst Notes
This IP operates within a high-risk subnet environment (0.8203 abuse density) but shows declining threat signals over the observation period. While not currently flagged as active malicious infrastructure, the combination of hosting classification, high-abuse neighborhood context, and DNSBL listings warrants continued monitoring. Consider blocking at perimeter controls if traffic from this address correlates with suspicious activity. The subnet 198.244.168.0/24 should be evaluated for broader reputation assessment given the 210 threat siblings identified.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk001-san98.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk001-san98.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 23% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-19 21:39:48 UTC |
| Last Seen | 2026-06-28 09:46:57 UTC |
| Profile Built | 2026-06-29 03:51:36 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 26 |
Full dossier details are available via our API.