# IPDEBRIEF INTELLIGENCE BRIEFING
Target: 198.244.183.16/32 | Classification: Moderate Risk | Date: 2026-06-20
---
## EXECUTIVE SUMMARY
IP 198.244.183.16 is a cloud-hosted infrastructure node operating under Ahrefs Pte Ltd Dmytro (ASN 16276, OVH) in London, United Kingdom. The IP presents a moderate risk profile (50/100) with no active threat indicators currently detected. However, the IP resides within a high-abuse-density subnet requiring contextual monitoring. No active services or open ports were observed.
---
## OWNERSHIP & INFRASTRUCTURE
- Organization: Ahrefs Pte Ltd Dmytro
- ASN: 16276 (OVH)
- Location: London, England, GB (750km accuracy radius)
- Infrastructure Type: Cloud Compute / Hosting
- DNS Hostname: proxy-uk004-san16.ahrefs.net
- Network Block: 198.244.128.0/17
No active services, open ports, or TLS certificates were detected. The IP appears firewalled with no HTTP/HTTPS services responding.
---
## THREAT INDICATORS
- Risk Score: 50 (Moderate)
- Abuse Confidence: Not calculated
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Blacklist Count: 0
- DNSBL Listings: 2 of 8 total lists
- Threat Feeds: Empty
- Campaign Correlation: None detected
---
## NETWORK CONTEXT
The IP is situated in subnet 198.244.183.16/24, which exhibits elevated abuse characteristics:
- Subnet Abuse Density: 0.793 (High)
- Classification: high_abuse
- Inherited Risk Score: 31
- Total Subnet Siblings: 256
- Active Siblings: 211
- Threat Siblings: 203
Risk distribution across queried neighbors: 41 medium-risk, 59 low-risk, 0 high-risk.
---
## OBSERVATION HISTORY
Analysis of 20 historical signals reveals consistent network classification with no significant risk escalation. Recent observations (2026-06-20) confirm:
- Stable cloud hosting classification
- Consistent UK geolocation inference
- Persistent high-abuse subnet classification
- No ownership changes detected
---
## RELATIONSHIPS
43 relationship entries identified, primarily network-level associations to OVH_282347340. No organizational or certificate-based relationships detected beyond the hosting provider.
---
## RECOMMENDED ACTIONS
Risk Score: 50 / 100 โ Probabilistic blocking recommended pending additional context.
Firewall Rules
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 198.244.183.16 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 198.244.183.16 drop` |
| nginx | `deny 198.244.183.16;` |
| pfSense | `198.244.183.16/32` |
| Cloudflare WAF | Block โ IPDebrief risk score 50 |
| AWS WAF | Address: 198.244.183.16/32 |
---
## ANALYST NOTES
This IP appears to be part of Ahrefs' proxy infrastructure but resides within an OVH subnet with documented abuse density. The moderate risk score is elevated primarily by neighborhood context rather than direct malicious activity. Recommend monitoring for pattern changes in outbound traffic to/from this IP, particularly given the subnet's high abuse density. No immediate threat action required, but maintain awareness of related subnet activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk004-san16.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk004-san16.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 22% | 9 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-20 05:44:19 UTC |
| Last Seen | 2026-06-28 10:56:24 UTC |
| Profile Built | 2026-06-29 05:01:51 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 24 |
Full dossier details are available via our API.