IP Intelligence Briefing: 198.244.183.1
Date: 2026-06-07
---
**1. Core Profile**
- Risk Score: 25 (Low Risk)
- Ownership: Registered to Ahrefs Pte Ltd Dmytro (ASN 16276, OVH provider).
- Geolocation: London, England, UK (plausible, 473.7 km from claimed coordinates).
- Network Role: CloudCompute infrastructure (OVH-hosted, no residential/mobile traffic).
- Threat Indicators: No malicious activity, no DNS/IP blacklists, no known attacker campaigns.
---
**2. Observation History**
- Recent Activity:
- Geo validation confirmed (RTT 86β99 ms, 5 probe packets).
- Subnet abuse density: 0.5781 (moderate risk in the 198.244.183.1/24 network).
- Operator score: 0.2174 (Minimal risk, per IPDebriefβs network operator analysis).
- Trend: No persistent threats or ownership changes detected.
---
**3. Relationships**
- Network Links:
- Part of OVH network (ASN 16276, OVH_282347340).
- DNS associations with proxy-uk004-san1.ahrefs.net (Ahrefsβ infrastructure).
- Subnet Context:
- 198.244.183.1/24 subnet has 256 IPs, with 116 threat siblings (abuse density: 45.31%).
- 11 IPs in the subnet have elevated risk scores (>50).
---
**4. Neighborhood Analysis**
- Subnet Risk: Mixed (abuse density 0.4531).
- Neighbor IPs:
- 100 total IPs in the subnet.
- 79 medium-risk (score 25β50) and 21 low-risk IPs.
- No direct malicious neighbors linked to this IP.
---
**5. Recommendations**
- Monitoring: Track subnet activity due to moderate abuse density.
- Firewall: No immediate action required for this IP, but consider blocking high-risk neighbors if they are not under your control.
- Context: Ahrefsβ infrastructure is legitimate, but ensure cloud services are configured securely.
Conclusion: 198.244.183.1 is a low-risk IP associated with Ahrefsβ cloud infrastructure. While the subnet has mixed risk, no direct threats are linked to this IP. SOC teams should monitor the subnet for anomalies.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | proxy-uk004-san1.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk004-san1.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 24% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-14 19:28:42 UTC |
| Last Seen | 2026-06-28 01:21:42 UTC |
| Profile Built | 2026-06-28 19:26:35 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 25 |
Full dossier details are available via our API.