# IP Intelligence Briefing: 198.244.183.48
## Executive Summary
IP 198.244.183.48 is a moderate-risk (40/100) residential cloud compute endpoint hosted on OVH infrastructure in London, GB. While the individual IP shows no direct threat indicators, the /24 subnet exhibits high abuse density (0.7422) with 190 out of 256 sibling IPs flagged as threats. The endpoint resolves to the ahrefs.net domain and is classified as hosting infrastructure with no active services.
---
## Technical Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 40 (Moderate Risk) |
| **ASN** | 16276 (OVH) |
| **Organization** | Ahrefs Pte Ltd Dmytro |
| **Geolocation** | London, England, GB |
| **Infrastructure** | CloudCompute / Hosting |
| **DNS Resolution** | proxy-uk004-san48.ahrefs.net |
| **Open Ports** | None detected |
| **Blacklist Status** | Clean (0 lists) |
## Threat Indicators
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Abuse Confidence Score: Not applicable
- Threat Feeds: No matches
- Known Campaigns: None
## Subnet Analysis (198.244.183.0/24)
- Abuse Density: 0.7422 (High)
- Classification: high_abuse
- Active Siblings: 176 / 256
- Threat Siblings: 190
- Risk Distribution: 100 medium-risk IPs, 0 high-risk, 0 low-risk
- Inherited Risk Score: 29
## Historical Observation Summary
- Total Observations: 21 signals
- Recent Activity: Last observed 2026-06-20
- Operator Score: Consistent at 0.2174 (Minimal)
- Threat Persistence: 0 days (not persistently malicious)
- Ownership Changes: 0
- Data Sufficiency: 6/6 dimensions covered across observations
## Network Relationships
- Primary Network: OVH_282347340
- Relationship Count: 36 entries
- BGP Prefix: 198.244.128.0/17
- Route Stability: Flagged as unstable
## Recommended Actions
Firewall Rules
iptables: `iptables -A INPUT -s 198.244.183.48 -j DROP`
nftables: `nft add rule inet filter input ip saddr 198.244.183.48 drop`
nginx: `deny 198.244.183.48;`
WAF Integration
Cloudflare WAF: Block IP 198.244.183.48 (risk score 40)
AWS WAF: Add address 198.244.183.48/32 to protected resources
## Analyst Assessment
The endpoint demonstrates moderate risk characteristics driven by subnet-level abuse patterns rather than direct malicious activity. The IP is associated with legitimate hosting infrastructure (ahrefs.net) but resides within a heavily abused subnet. Recommend monitoring traffic patterns and evaluating the necessity of blocking based on observed threat activity. The subnet's high abuse density suggests broader infrastructure compromise risk.
Priority: Monitor
Action Required: Review inbound traffic patterns, consider blocking if threat activity correlates
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk004-san48.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk004-san48.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 21% | 9 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-20 05:44:19 UTC |
| Last Seen | 2026-06-28 10:58:40 UTC |
| Profile Built | 2026-06-29 05:02:59 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 24 |
Full dossier details are available via our API.