# IP Intelligence Briefing: 198.244.183.214
## Executive Summary
IP 198.244.183.214 presents a Moderate Risk (Score: 40) profile. The address is associated with Ahrefs Pte Ltd Dmytro infrastructure hosted on OVH cloud compute in London, England. While the IP shows legitimate enterprise characteristics, it resides within a high-abuse density subnet (198.244.183.0/24) with 75.39% abuse classification and 193 threat siblings out of 256 total addresses.
## Ownership & Infrastructure
- Organization: Ahrefs Pte Ltd Dmytro
- ASN: 16276 (OVH)
- Location: London, England, GB (GeoConsensus: Valid)
- Infrastructure: Cloud hosting environment with firewalled/no services status
- BGP Prefix: 198.244.128.0/17
- Route Stability: Unstable (routeChanges30d: 0, isRouteStable: false)
## DNS & Network Fingerprint
- PTR Hostname: proxy-uk004-san214.ahrefs.net
- Forward Resolution: proxy-uk004-san214.ahrefs.net (confirmed)
- DNSSEC: Valid
- HTTP Services: None detected (firewalled)
- TLS Certificate: None detected
## Threat Indicators
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Blacklist Count: 0
- DNSBL Listed: 1 of 8 total lists
- Abuse Confidence Score: Not calculated
- Campaign Correlation: No matches (certMatches: 0, correlatedIps: 0)
## Neighborhood Risk Assessment
The /24 subnet exhibits HIGH abuse classification with concerning density metrics:
- Abuse Density: 0.7539 (75.39%)
- Active Siblings: 176 of 256 total IPs
- Threat Siblings: 193 IPs flagged as threats
- Risk Distribution: 100% Medium Risk (0 High, 0 Low)
- Inherited Risk: 30 (neighborhood-level risk)
## Observations Timeline
Recent activity observed on 2026-06-15:
- Port scanning activity detected
- DNS resolution to ahrefs.net confirmed
- Operator score: 0.2174 (Minimal)
- 22 total observations recorded
- Threat observation count: 1
## Recommended Security Actions
Based on the moderate risk profile and high-abuse neighborhood context:
Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 198.244.183.214 -j DROP
# nftables
nft add rule inet filter input ip saddr 198.244.183.214 drop
# nginx
deny 198.244.183.214;
```
WAF Recommendations:
- Cloudflare WAF: Block IP with description "IPDebrief risk score 40"
- AWS WAF: Add address 198.244.183.214/32 with description "IPDebrief risk 40"
## Intelligence Assessment
This IP represents cloud infrastructure associated with a legitimate SEO services provider (Ahrefs) operating within an elevated-risk hosting environment. The moderate risk score (40) combined with the high-abuse neighborhood (198.244.183.0/24) suggests the subnet may host both legitimate services and malicious actors sharing infrastructure.
Recommendation: Implement blocking rules at perimeter security devices while maintaining awareness of the subnet's elevated risk profile. Monitor for any lateral movement or related threat activity within the OVH 198.244.128.0/17 block. The IP's association with Ahrefs infrastructure warrants investigation to determine if the moderate risk stems from neighborhood contamination or legitimate hosting practices.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk004-san214.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk004-san214.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 47% | 2 | 5 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 26% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-22 09:12:28 UTC |
| Last Seen | 2026-06-28 18:26:23 UTC |
| Profile Built | 2026-06-29 06:29:43 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 26 |
Full dossier details are available via our API.