## IP Intelligence Briefing: 198.244.183.6
Classification: Moderate Risk | Risk Score: 50/100 | Last Updated: 2026-06-28
Ownership & Infrastructure
- ASN: 16276 (Ahrefs Pte Ltd Dmytro)
- Provider: OVH
- Geolocation: London, England, GB
- Registered Organization: Ahrefs Pte Ltd Dmytro
- DNS Resolution: proxy-uk004-san6.ahrefs.net (ahrefs.net)
- Network Classification: Hosting infrastructure, firewalled/no services exposed
- BGP Prefix: 198.244.128.0/17
- Route Stability: Unstable (isRouteStable: false)
Threat Indicators
- Blacklist Status: Listed on 2 of 8 DNSBLs
- Threat Indicators: None directly attributed
- Tor/VPN/Proxy: Not detected (isTor: false, isProxy: false, isVpn: false)
- Campaign Correlation: No known campaign matches
Neighborhood Analysis (198.244.183.0/24)
- Abuse Density: 0.7773 (High Abuse Classification)
- Subnet Population: 256 total IPs, 200 active
- Threat Correlation: 199 of 200 active siblings flagged as threats
- Risk Distribution: Medium risk: 68%, Low risk: 32%, High risk: 0%
Historical Signals
- Observation Count: 22 historical signals
- Recent Activity: Signals observed through 2026-06-28
- Subnet Risk History: Classified as "high_abuse" with 0.7773 abuse density (2026-06-20)
- Provider Consistency: OVH hosting confirmed across observations
- Threat Persistence: No persistent malicious behavior detected
Relationship Graph
- Network Associations: 44 relationships identified, primarily same-network (OVH_282347340)
- Infrastructure: Associated with OVH hosting infrastructure
Recommended Security Actions
Immediate Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 198.244.183.6 -j DROP
# nftables
nft add rule inet filter input ip saddr 198.244.183.6 drop
# pfSense
198.244.183.6/32 (Block rule)
```
WAF Integration:
- Cloudflare WAF: Block IP with expression: `ip.src eq 198.244.183.6`
- AWS WAF: Add to blocklist: `198.244.183.6/32`
Analyst Assessment
This IP exhibits moderate risk characteristics typical of hosting infrastructure within a high-abuse subnet. The 198.244.183.0/24 subnet demonstrates concentrated threat activity with 199 of 200 active neighbors flagged. While the target IP shows no direct threat indicators, its neighborhood context and DNSBL listings warrant blocking. The IP resolves to an Ahrefs-related hostname but is classified as hosting infrastructure with no open services, suggesting potential misuse or compromised infrastructure.
Recommended Action: Block at perimeter firewall and WAF layers. Monitor subnet 198.244.183.0/24 for additional threat correlation. Investigate associated domains for potential abuse patterns.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk004-san6.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk004-san6.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 41% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 22% | 1 | 2 |
| geolocation | 31% | 2 | 3 |
| Overall | 24% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-18 03:22:28 UTC |
| Last Seen | 2026-06-28 06:10:36 UTC |
| Profile Built | 2026-06-29 06:15:54 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 26 |
Full dossier details are available via our API.