# IP Intelligence Briefing: 198.244.183.143/32
## Executive Summary
Risk Classification: Low Risk (Score: 25/100)
IP 198.244.183.143 is a cloud infrastructure endpoint associated with Ahrefs Pte Ltd, hosted on OVH network infrastructure. The IP shows no active threat indicators and maintains low-risk characteristics.
## Infrastructure Profile
- Ownership: Ahrefs Pte Ltd Dmytro (ASN: 16276)
- Provider: OVH (CloudCompute infrastructure)
- Geolocation: London, England, GB (GeoConsensus: Yes, GeoPlausible: Yes)
- Network Role: Cloud-hosted, hosting provider classification
- DNS: Forward resolves to proxy-uk004-san143.ahrefs.net
- Services: No open ports detected (firewalled configuration)
- TLS/HTTP: No active services, no certificates, no HTTP headers detected
## Threat Assessment
- Reputation Sources: None identified
- Blacklist Status: 0 blacklists, 1 DNSBL listing (minimal impact)
- Known Campaigns: None
- Threat Indicators: None (not known attacker, not Tor exit, not spam source)
- Abuse Confidence Score: Not applicable
- Campaign Likelihood: None
## Control Plane Analysis
- BGP Prefix: 198.244.128.0/17
- Origin ASN: 16276
- RPKI State: Not available
- IRR Consistency: Not available
- Route Stability: Not stable (routeChanges30d: 0 but isRouteStable: false)
- DNSSEC: Valid
- CAA Records: Present
- Operator Score: 0.2174 (Minimal)
## Temporal Analysis
- Observation Count: 1 threat observation recorded
- Ownership Changes: 0 changes
- Threat Persistence: 0 days
- Persistently Malicious: No
## Neighborhood Analysis (198.244.183.0/24)
- Subnet Classification: Mixed
- Abuse Density: 42.19%
- Total Siblings: 256
- Active Siblings: 213
- Threat Siblings: 108
- Risk Distribution: 0 High, 76 Medium, 24 Low
## Historical Observations (23 total)
Recent signals indicate:
- Domain resolution to ahrefs.net (confidence: 0.80)
- CAA records present
- Cloud infrastructure confirmed (OVH) (confidence: 0.90)
- GB geolocation inferred (confidence: 0.28)
- Operator score: Minimal (confidence: 0.30)
## Related Entities
- Network: OVH_282347340 (63 relationship entries)
- Primary Hostname: proxy-uk004-san143.ahrefs.net
- No certificate or organization relationships identified
## Recommended Actions
- No immediate blocking required โ IP maintains low-risk profile
- Monitoring: Continue standard monitoring given 42.19% neighborhood abuse density
- Firewall Rules: No specific recommendations generated
- WAF Configuration: No specific rules required based on current risk profile
## Intelligence Context
This IP represents a legitimate cloud-hosted endpoint for Ahrefs, a SEO analytics platform. The infrastructure is properly registered under ARIN with OVH as the cloud provider. No malicious activity has been observed despite moderate neighborhood abuse density. The IP appears to be a standard cloud infrastructure component with no anomalous behavior detected.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk004-san143.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk004-san143.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 32% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 17% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 24% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-11 21:10:47 UTC |
| Last Seen | 2026-06-27 19:59:54 UTC |
| Profile Built | 2026-06-28 14:04:56 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 29 |
Full dossier details are available via our API.