IP Intelligence Briefing: 198.244.183.212
*Generated via IPDebrief Analysis*
---
**1. Core Profile**
- Reputation: Moderate Risk (Risk Score: 40)
- Ownership:
- ASN: 16276 (OVH SAS)
- Organization: Ahrefs Pte Ltd Dmytro
- Geolocation: London, England, UK (inferred via DNS and network signals)
- Network Role: Cloud compute infrastructure (OVH-hosted, no residential/mobile indicators)
- Threat Indicators:
- No direct malicious activity detected (no known attacker, spam, or Tor exit node).
- DNSBL Listings: 1/8 total lists (low-severity, likely false positives).
---
**2. Observation History**
- Recent Activity (June 14, 2026):
- DNS resolution for `proxy-uk004-san212.ahrefs.net` (Ahrefs subdomain).
- Subnet abuse density: High (69.92% of 198.244.183.0/24 subnet flagged).
- Inherited Risk: 27 (subnetwork-level risk from neighboring IPs).
- TLS/HTTP: No open services or certificates detected.
---
**3. Relationships & Network Context**
- Linked Entities:
- Same network: 256 IPs in 198.244.183.0/24 subnet.
- Threat Siblings: 179 IPs flagged in the subnet (high abuse density).
- Parent ASN: AS16276 (OVH SAS), classified as "Basic" operator risk.
- Subnet Classification: "High Abuse" (27% inherited risk, 139 active IPs).
---
**4. Neighborhood Analysis**
- Subnet Risk Distribution:
- 100% of neighbors in 198.244.183.0/24 have moderate risk (score: 40).
- Abuse Density: 69.92% (high-risk subnet).
- Notable Neighbors:
- 198.244.183.0/24 (same subnet, moderate risk).
---
**5. Recommendations**
- Monitor Subnet: The high abuse density in the subnet suggests potential for lateral movement or shared infrastructure risks.
- Verify DNSBL Listings: Investigate why this IP appears on 1/8 DNSBLs (e.g., false positives or misconfigurations).
- Secure Cloud Instance: Ensure OVH-hosted server has strict access controls and firewall rules (e.g., block all ports except required services).
- Check for Compromises: Correlate with other IPs in the subnet for signs of coordinated malicious activity.
Conclusion: This IP is a legitimate Ahrefs cloud server, but its subnet has a high abuse density. SOC teams should monitor for anomalies and ensure strict security controls to mitigate shared network risks.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk004-san212.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk004-san212.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 43% | 2 | 5 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 25% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:06 UTC |
| Last Seen | 2026-06-27 02:40:34 UTC |
| Profile Built | 2026-06-27 20:46:09 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 33 |
Full dossier details are available via our API.