IPDebrief

198.244.183.194

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING

Target: 198.244.183.194/32

Classification: Moderate Risk โ€“ Cloud Infrastructure Node

Date: Current Intelligence Cycle

---

## EXECUTIVE SUMMARY

IP 198.244.183.194 is a cloud computing endpoint hosted within OVH infrastructure, operated by Ahrefs Pte Ltd. The IP shows moderate risk characteristics (Risk Score: 40) with no direct threat indicators. The address belongs to a high-abuse density subnet (198.244.183.0/24) requiring contextual monitoring. No immediate blocking actions recommended; maintain standard operational procedures.

---

## OWNERSHIP & INFRASTRUCTURE

AttributeValue
**ASN**16276 (OVH SAS)
**Organization**Ahrefs Pte Ltd Dmytro
**Geolocation**London, England, GB
**Infrastructure**OVH Cloud Compute (Hosting)
**Network Class**Cloud Infrastructure
**DNS Resolution**proxy-uk004-san194.ahrefs.net
**Domain**ahrefs.net

The IP is part of Ahrefs' UK-based hosting infrastructure. The PTR hostname indicates this is a proxy or server endpoint within their distributed network architecture.

---

## THREAT ASSESSMENT

Risk Indicators

Service Exposure

The target is a passive infrastructure node with no active service exposure. This significantly reduces immediate threat potential despite subnet-level abuse characteristics.

---

## SUBNET CONTEXT (198.244.183.0/24)

MetricValue
**Abuse Density**0.7891 (High)
**Classification**high_abuse
**Total Siblings**256
**Active Siblings**211
**Threat Siblings**202
**Inherited Risk**31/100

Analysis: The /24 subnet exhibits elevated abuse activity. Of 256 potential IPs, 202 are classified as threats and 211 are actively generating signals. This suggests coordinated infrastructure usage within the subnet. However, the target IP itself shows no direct malicious activity.

Neighboring IP Risk Distribution:

---

## OBSERVATION HISTORY

Signal Count: 22 observations recorded

Most Recent Activity: June 20, 2026

Key Historical Signals:

1. Subnet Classification: High abuse density (0.7891) โ€“ consistent across recent observations

2. Provider Classification: OVH cloud infrastructure โ€“ stable

3. Geolocation: London, GB โ€“ with 750km accuracy radius

4. Network Path: 198.244.128.0/17 BGP prefix โ€“ stable assignment

5. Operator Score: 0.2174 (Minimal) โ€“ indicates low operator-level threat

The IP demonstrates persistent infrastructure characteristics with no evidence of behavior change or threat escalation.

---

## RELATIONSHIP ANALYSIS

Detected Relationships: 52 total

Primary Classification: Same Network (OVH_282347340)

All relationships indicate the IP belongs to OVH's broader network infrastructure. No associations with known malicious campaigns or campaign-related entities were identified.

---

## RECOMMENDED ACTIONS

Firewall Rules

Status: NO ACTION REQUIRED

No blocking rules recommended. The IP shows no active malicious behavior and is part of legitimate cloud infrastructure.

Monitoring Recommendations

1. Passive Monitoring: Continue standard passive scanning for this IP

2. Subnet Awareness: Monitor 198.244.183.0/24 for broader threat patterns

3. Threshold Monitoring: Flag any services opening on this IP that were previously firewalled

4. Correlation: Cross-reference with Ahrefs threat intelligence feeds if available

SOC Analyst Notes

---

## END OF BRIEFING

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฌ๐Ÿ‡ง United Kingdom
RegionEngland
CityLondon
TimezoneEurope/London
Latitude51.51
Longitude-0.13

๐Ÿข Ownership & Registration

OrganizationAhrefs Pte Ltd Dmytro
ASNAS16276
Network Nameโ€”
CIDR Blockโ€”
RIRARIN
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRproxy-uk004-san194.ahrefs.net
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesproxy-uk004-san194.ahrefs.net

๐Ÿ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAAPresent

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting โ€” Infrastructure provider without advanced routing
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
29%
24
routing
13%
11
services
12%
22
ownership
24%
23
reputation
31%
13
geolocation
33%
23
Overall24%1016
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-21 20:59:56 UTC
Last Seen2026-06-28 15:45:35 UTC
Profile Built2026-06-29 03:49:18 UTC
Data FreshnessLive
Signal Types22
Total Observations26
๐Ÿ” 22 signal types ยท 26 observations collected
This report is generated from 22+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.