# IP Intelligence Briefing: 198.244.183.195
## Executive Summary
IP address 198.244.183.195 is classified as Moderate Risk (risk score: 40) with no direct threat indicators. The IP is hosted within Ahrefs infrastructure on OVH cloud compute infrastructure in London, GB. While the IP itself lacks active threat markers, its subnet exhibits elevated abuse density (0.6328), warranting monitoring.
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **ASN** | 16276 (Ahrefs Pte Ltd Dmytro) |
| **Network Provider** | OVH |
| **Geolocation** | London, England, GB |
| **Infrastructure Type** | Cloud Compute |
| **Classification** | Hosted / Cloud |
| **Open Ports** | None detected |
## Network Context
Subnet Analysis (198.244.183.0/24):
- Classification: High Abuse
- Abuse Density: 0.6328 (elevated)
- Total Siblings: 256
- Active Siblings: 126
- Threat Siblings: 162
- Inherited Risk Score: 25
This subnet shows concentrated malicious activity, with 63% of active IPs flagged as threats.
## DNS & Hostname Resolution
- PTR Record: proxy-uk004-san195.ahrefs.net
- Domain: ahrefs.net (legitimate SEO analytics provider)
- Forward Resolution: Confirmed (1 host)
- Email Authentication: SPF, DMARC not configured
## Threat Assessment
Current Risk Indicators:
- โ No active threat indicators
- โ Not a known attacker
- โ Not a spam source
- โ Not a Tor exit node
- โ No blacklist listings (0/8)
Historical Activity:
- Total Observations: 22
- DNS Blacklist Activity: 1 listing observed (2026-06-15, High severity)
- Threat Persistence: 0 days
- Status: Not persistently malicious
## Control Plane
- BGP Prefix: 198.244.128.0/17
- Route Stability: False (route changes detected)
- RPKI State: Valid
- DNSSEC: Valid
- Operator Score: 0.2609 (Basic)
## Recommended Actions
Firewall Rules (Block Recommended)
```bash
# iptables
iptables -A INPUT -s 198.244.183.195 -j DROP
# nftables
nft add rule inet filter input ip saddr 198.244.183.195 drop
# pfSense
198.244.183.195/32
```
WAF Recommendations
- Cloudflare WAF: Block IP with expression `ip.src eq 198.244.183.195`
- AWS WAF: Add 198.244.183.195/32 to IP Set for blocking
Strategic Guidance
1. Monitor, Don't Block Immediately: No active threat indicators support aggressive blocking. The moderate risk score (40) with inherited risk from high-abuse subnet suggests situational awareness is preferable to immediate blocking.
2. Watch List Status: Add to monitoring due to high-abuse subnet context. Review if any downstream activity correlates with the subnet's threat patterns.
3. Verify Legitimate Use: Given ahrefs.net domain association, consider whether blocking would disrupt legitimate business operations.
4. Subnet-Wide Assessment: Evaluate whether broader subnet blocking (198.244.183.0/24) is warranted given 63% abuse density, though this may impact legitimate services.
---
*Analysis generated by IPDebrief Intelligence Platform. All data based on current observations as of analysis timestamp.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk004-san195.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk004-san195.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 22% | 9 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-20 05:44:19 UTC |
| Last Seen | 2026-06-28 10:56:29 UTC |
| Profile Built | 2026-06-29 05:01:51 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 24 |
Full dossier details are available via our API.