IP Intelligence Briefing: 198.244.183.101
Date: 2026-06-09
---
**1. Core Profile**
- Risk Score: 40 (Moderate Risk)
- Ownership:
- ASN: 16276 (OVH)
- Organization: Ahrefs Pte Ltd Dmytro
- Geolocation: London, England, UK (high plausibility)
- Network Role: CloudCompute instance (OVH) with no direct threat indicators.
- Threat Status: No malicious indicators (no blacklists, spam, or known attacker activity).
---
**2. Observation History**
- DNS Associations: Linked to `proxy-uk004-san101.ahrefs.net` (Ahrefs).
- Geolocation Consistency: High accuracy (750m radius, 93.8ms avg RTT).
- Network Stability: Subnet (`198.244.183.101/24`) has 63% abuse density, with 162 threat siblings.
---
**3. Relationships**
- Network: Same subnet as OVH network `OVH_282347340`.
- DNS: Strong association with Ahrefsβ proxy hostname.
- No Direct Threat Links: No correlated IPs, campaigns, or certificates detected.
---
**4. Neighborhood Analysis**
- Subnet: `198.244.183.101/24` (256 total IPs).
- Risk Distribution:
- 100 active IPs (mixed risk scores, 40β50).
- High abuse density (63%), but no direct malicious activity on this IP.
- Recommendation: Monitor subnet for anomalous traffic, as neighboring IPs show mixed risk profiles.
---
**5. Actionable Insights**
- No Immediate Mitigation Needed: IP is associated with a legitimate cloud provider and shows no malicious behavior.
- Monitor Subnet: Given the high abuse density in the subnet, investigate neighboring IPs for potential misconfigurations or compromised hosts.
- Verify DNS Security: Ensure DNSSEC and CAA records are properly configured for `ahrefs.net` to prevent spoofing.
---
Summary: 198.244.183.101 is a legitimate cloud instance tied to Ahrefs, with no direct threat indicators. However, its subnet exhibits elevated abuse density, warranting closer scrutiny. SOC teams should prioritize monitoring the broader network for suspicious activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | proxy-uk004-san101.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk004-san101.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 23% | 9 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-20 11:46:14 UTC |
| Last Seen | 2026-06-28 11:40:27 UTC |
| Profile Built | 2026-06-29 05:44:58 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 24 |
Full dossier details are available via our API.