# IP INTELLIGENCE BRIEFING: 198.244.183.108
## EXECUTIVE SUMMARY
IP address 198.244.183.108 presents a moderate risk profile (Risk Score: 40) with operational characteristics consistent with a cloud-hosted service. The IP is registered to Ahrefs Pte Ltd Dmytro via OVH infrastructure (ASN 16276) and resolves to proxy-uk004-san108.ahrefs.net. While the IP shows no direct threat indicators, it resides within a high-abuse density subnet (198.244.183.0/24) with an abuse density score of 0.793.
---
## OWNERSHIP & GEOSPATIAL ANALYSIS
| Attribute | Value |
|---|---|
| **Organization** | Ahrefs Pte Ltd Dmytro |
| **ASN** | 16276 (OVH) |
| **Location** | London, England, GB |
| **Infrastructure Type** | Cloud Compute / Hosting |
| **RIR** | ARIN |
The IP is associated with the ahrefs.net domain namespace and resolves to a proxy hostname. DNSSEC validation is present and configured. The control plane indicates route instability over the 30-day window.
---
## THREAT ASSESSMENT
Direct Threat Indicators:
- No known attack campaigns
- Not a Tor exit node, known attacker, or spam source
- Zero blacklist entries in the profile
- DNSBL listed on 1 of 8 threat feeds
Risk Factors:
- Neighborhood Context: High-abuse subnet classification with 203 threat siblings out of 211 active IPs
- Subnet Abuse Density: 0.793 (elevated)
- Inherited Risk Score: 31 from /24 subnet context
- Historical Signals: 22 observations recorded; 1 threat observation detected
Network Role: Firewalled / No Services detected (no open ports, no TLS certificates, no active services)
---
## OBSERVATION HISTORY
The IP has been observed across 22 signal events. Recent activity includes:
- 2026-06-28: DNS validation signals (CAA records, DNSSEC) with minimal operator scores
- 2026-06-20: Subnet abuse classification confirmed at 0.793 density
- Threat Persistence: Single threat observation; not persistently malicious
The historical trend shows stable operational characteristics with no escalation in threat signals.
---
## RELATED ENTITIES
Network Relationships: 43 relationships identified, primarily Same Network associations to OVH_282347340. No certificate, hostname, or organization correlations beyond the ahrefs.net namespace.
---
## RECOMMENDED SECURITY ACTIONS
Based on the moderate risk score (40) and high-abuse neighborhood context, the following firewall rules are recommended:
| Platform | Rule |
|---|---|
| **iptables** | `iptables -A INPUT -s 198.244.183.108 -j DROP` |
| **nftables** | `nft add rule inet filter input ip saddr 198.244.183.108 drop` |
| **nginx** | `deny 198.244.183.108;` |
| **pfSense** | `198.244.183.108/32` |
| **Cloudflare WAF** | Block with expression: `ip.src eq 198.244.183.108` |
| **AWS WAF** | Add to IPSet: `198.244.183.108/32` |
Note: These recommendations are probabilistic. Integration with additional threat signals and organizational policy is advised before implementing blocks.
---
## ANALYST NOTES
The IP operates within a legitimate enterprise hosting environment (Ahrefs) but exists in a subnet with elevated abuse activity. The lack of direct threat indicators suggests the IP itself is not malicious, though the neighborhood context warrants defensive positioning. Consider monitoring rather than immediate blocking if traffic patterns align with expected service behavior. If inbound traffic from this IP is unexpected, blocking is justified given the high-abuse subnet classification.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk004-san108.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk004-san108.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 23% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-21 14:56:53 UTC |
| Last Seen | 2026-06-28 13:56:32 UTC |
| Profile Built | 2026-06-29 01:59:48 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 24 |
Full dossier details are available via our API.