# IP Intelligence Briefing: 198.244.183.224
Classification: Moderate Risk | Date: 2026-06-28 | Risk Score: 40
---
## Executive Summary
IP address 198.244.183.224 operates as a cloud-hosted infrastructure endpoint within OVH's network in London, England. The IP is classified as moderate risk (40/100) with significant neighborhood-level abuse indicators. No direct threat indicators were observed, though the subnet exhibits high abuse density (0.793) with 203 threat-sibling IPs identified.
---
## Technical Profile
Network Ownership:
- ASN: 16276
- Organization: Ahrefs Pte Ltd Dmytro
- RIR: ARIN
- BGP Prefix: 198.244.128.0/17
- Route Stability: False
Geolocation:
- Country: GB (England, London)
- Timezone: Europe/London
- Geographic Accuracy: 750km radius
Network Role:
- Provider: OVH
- Infrastructure Type: Cloud
- Classification: Hosting
- Service Status: Firewalled / No Services
- No Open Ports Detected
DNS Resolution:
- PTR Hostname: proxy-uk004-san224.ahrefs.net
- Domain: ahrefs.net
- Forward Resolution: Confirmed (1 hostname)
- CAA Records: Present
- DNSSEC: Valid
---
## Threat Assessment
Threat Indicators:
- Blacklist Count: 0
- DNSBL Listings: 1 of 8 lists
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Active Campaigns: None detected
Abuse Confidence: Not available in current dataset
---
## Neighborhood Analysis (198.244.183.0/24)
Subnet Statistics:
- Total IPs: 256
- Active Siblings: 211
- Threat Siblings: 203
- Abuse Density: 0.793 (High)
- Inherited Risk Score: 31
Risk Distribution:
- High Risk: 0
- Medium Risk: 36
- Low Risk: 64
The subnet exhibits elevated abuse characteristics consistent with shared hosting infrastructure.
---
## Observation History
Total Observations: 21 signals tracked
Recent Activity (2026-06-28):
- Listed on 8 threat intelligence feeds
- Listed Count: 2
- Maximum Severity: High
- Provider Classification: OVH Cloud (CloudCompute)
- Abuse Density Signal: 0.793 (high_abuse classification)
Temporal Analysis:
- Ownership Changes: 0
- Threat Persistence Days: 0
- Persistently Malicious: No
- Threat Observation Count: 1
---
## Relationship Graph
Connected Entities:
- 36 relationships identified
- Primary Network Association: OVH_282347340 (multiple instances)
- No certificate or hostname relationships detected
- No correlated IPs in known campaigns
---
## Recommended Security Actions
Firewall Rules (Risk Score 40):
- iptables: `iptables -A INPUT -s 198.244.183.224 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 198.244.183.224 drop`
- nginx: `deny 198.244.183.224;`
- pfSense: `198.244.183.224/32`
- Cloudflare WAF: Block with description "IPDebrief risk score 40"
- AWS WAF: IP Set: 198.244.183.224/32
Assessment: No specific service-based recommendations; blocking recommended based on neighborhood risk profile and moderate risk classification.
---
## Intelligence Conclusions
1. The IP represents legitimate hosting infrastructure (OVH cloud) associated with ahrefs.net domain
2. No active malicious indicators detected at the individual IP level
3. Subnet-level abuse density is elevated (0.793) with 203 threat-sibling IPs
4. Recent listing activity (8 feeds, 2 active listings) suggests ongoing monitoring of this IP
5. Route instability noted (bgpPrefix 198.244.128.0/17)
Recommendation: Apply blocking rules at perimeter controls due to neighborhood risk profile, but monitor for legitimate business use given the ahrefs.net association.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk004-san224.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk004-san224.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 22% | 9 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-20 05:44:19 UTC |
| Last Seen | 2026-06-28 10:57:39 UTC |
| Profile Built | 2026-06-29 05:02:59 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 23 |
Full dossier details are available via our API.