# IP Intelligence Briefing: 198.244.183.156
## Executive Summary
IP address 198.244.183.156 is a moderate-risk (score: 40) cloud hosting endpoint operated by OVH in London, United Kingdom. The IP resolves to afirewalled infrastructure with no active services, but exists within a high-abuse subnet (abuse density: 0.7422) containing 190 threat-sibling IPs. Recommended for defensive blocking with contextual awareness of legitimate business operations (Ahrefs).
## Technical Profile
- Risk Score: 40 (Moderate Risk)
- ASN: 16276 (OVH)
- Organization: Ahrefs Pte Ltd Dmytro
- Geolocation: London, England, GB (750km accuracy)
- Infrastructure Type: CloudCompute, Hosting
- Service Status: Firewalled / No Services Detected
- DNS Resolution: proxy-uk004-san156.ahrefs.net
## Threat Indicators
- Abuse Confidence Score: Not elevated
- Blacklist Status: Listed on 1 of 8 DNSBL feeds (high severity)
- Tor Exit Node: False
- Known Attacker: False
- Spam Source: False
- Campaign Correlation: None detected
- Threat Persistence: Not persistently malicious (0 threat observation days)
## Subnet Context (198.244.183.0/24)
- Abuse Density Classification: High Abuse (0.7422)
- Total Subnet IPs: 256
- Active Siblings: 176
- Threat Siblings: 190
- Inherited Risk Score: 29
- Neighbor Risk Distribution: 100 medium-risk neighbors, 0 high-risk
## Network Relationships
- Control Plane Operator Score: 0.2174 (Minimal)
- BGP Prefix: 198.244.128.0/17
- Route Stability: False
- DNSSEC Valid: True
- Route Changes (30d): 0
- Relationships Count: 38 (primarily same-network OVH_282347340 entries)
## Historical Observations
Recent signal activity (2026-06-15) indicates:
- Operator score maintained at 0.2174 (minimal)
- DNS and geolocation signals stable
- One high-severity DNSBL listing observed
- Subnet abuse density consistently high (0.7422)
- No ownership changes detected
## Recommended Actions
Immediate Mitigation
Block traffic at the following security layers:
Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 198.244.183.156 -j DROP
# nftables
nft add rule inet filter input ip saddr 198.244.183.156 drop
# nginx
deny 198.244.183.156;
```
Cloud Platform Integration:
- Cloudflare WAF: Block with expression `ip.src eq 198.244.183.156`
- AWS WAF: Add IP 198.244.183.156/32 to block set
- pfSense: Configure rule for 198.244.183.156/32
## Intelligence Assessment
The IP represents a legitimate hosting endpoint (Ahrefs infrastructure) operating within an over-utilized, high-abuse subnet. The moderate risk score reflects contextual subnet contamination rather than direct malicious activity. The firewalling status and lack of open services suggest defensive positioning, but the high-abuse neighborhood warrants continued monitoring.
Analyst Notes: Correlate with known Ahrefs operational ranges. Consider allowing if traffic pattern matches expected business hours and legitimate user agents. The single DNSBL listing requires investigation but does not indicate active abuse from this specific endpoint.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk004-san156.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk004-san156.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 23% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-21 14:56:54 UTC |
| Last Seen | 2026-06-28 13:56:24 UTC |
| Profile Built | 2026-06-29 08:01:29 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 25 |
Full dossier details are available via our API.