Threat Intelligence Briefing: IP 198.244.183.229/32
Summary:
The IP address 198.244.183.229/32 was observed in a network environment as part of routine monitoring activities. The analysis focused on its operational profile, historical behavior, relational dynamics, and surrounding network context. The information gathered provides insights into potential security implications for network defenders.
Observation History:
- Past Activity: Historical data indicated sporadic communication with external domains known for hosting content delivery networks (CDNs). These connections were typically low volume and short-lived, suggesting a potential use for legitimate content distribution purposes.
- Traffic Patterns: Traffic analysis revealed periodic bursts of outbound connections during off-peak hours. This pattern aligns with typical behaviors observed in environments where batch processing or scheduled data synchronization occurs.
Relationships:
- Domain Associations: The IP address was linked to several domain registrations with minimal WHOIS information, often employing privacy protection services. This is a common practice but can also obscure the true origin of activities.
- Known Affiliations: There were no direct associations with high-risk threat actors or known malicious campaigns in the reviewed datasets. However, the use of privacy-protected domains warrants cautious monitoring for any anomalous behavior.
Neighborhood Data:
- Subnet Analysis: Within the broader /24 subnet, the IP address 198.244.183.229/32 was part of a mixed-use network. The subnet hosted a variety of services, including web hosting and legitimate business operations, alongside a few addresses with questionable reputations.
- Co-location Observations: Several IPs within the same subnet exhibited similar traffic patterns, suggesting a potential co-location of services. This could indicate shared infrastructure usage, which might be leveraged for both legitimate and illegitimate purposes.
Actionable Insights:
1. Monitoring: Continue monitoring traffic from and to 198.244.183.229/32, especially during identified peak periods. Look for deviations from established patterns that could indicate misuse or compromise.
2. Domain Scrutiny: Investigate domains associated with the IP for any sudden changes in activity or reputation. Utilize threat intelligence feeds to cross-reference any emerging threats linked to these domains.
3. Subnet Vigilance: Maintain awareness of the broader /24 subnet. Implement network segmentation and access controls to mitigate potential risks from co-located services.
4. Anomaly Detection: Enhance anomaly detection systems to flag unusual outbound connections or data volumes, particularly during off-peak hours, to preemptively identify potential exfiltration attempts or unauthorized activities.
This briefing provides a foundational understanding of the IP address in question, enabling SOC teams to implement informed defensive strategies.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk004-san229.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk004-san229.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:06 UTC |
| Last Seen | 2026-06-27 02:40:54 UTC |
| Profile Built | 2026-06-27 20:46:09 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 31 |
Full dossier details are available via our API.