# IP INTELLIGENCE BRIEFING
Target: 198.244.183.71/32
Report Date: 2026-06-19
Classification: Moderate Risk
---
## EXECUTIVE SUMMARY
IP 198.244.183.71 is a cloud compute resource hosted by OVH (ASN 16276) in London, United Kingdom. The IP resolves to the ahrefs.net domain infrastructure and is associated with Ahrefs Pte Ltd Dmytro. Risk scoring indicates moderate risk (40/100) with no active threat indicators detected. The IP shows no evidence of malicious activity, but the /24 subnet exhibits elevated abuse density requiring contextual awareness.
---
## OWNERSHIP & INFRASTRUCTURE
- Provider: OVH
- ASN: 16276 (OVH)
- Organization: Ahrefs Pte Ltd Dmytro
- Location: London, England, GB
- Geographic Confidence: Validated (RTT avg: 87.6ms, 5 probes)
- Infrastructure Type: CloudCompute
- Network Role: Firewalled/No Services Detected
---
## DNS & SERVICE ANALYSIS
- PTR Hostname: proxy-uk004-san71.ahrefs.net
- Domain: ahrefs.net
- DNSSEC: Valid
- Open Ports: None detected
- TLS Certificate: Not observed
- HTTP Services: No active web services
---
## THREAT ASSESSMENT
- Risk Score: 40 (Moderate)
- Abuse Confidence: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Blacklist Count: 0
- Threat Feeds: None
- Campaign Associations: None
- Threat Observation Count: 1 (non-persistent)
- Is Persistently Malicious: No
---
## NEIGHBORHOOD ANALYSIS
Subnet: 198.244.183.0/24
- Abuse Density: 0.5703 (High)
- Total Siblings: 256
- Active Siblings: 111
- Threat Siblings: 146
- Inherited Risk Score: 22
- Classification: High Abuse
- Risk Distribution: 100 Medium, 0 High, 0 Low
*Note: The subnet exhibits elevated abuse activity, though this target IP shows no direct malicious indicators.*
---
## OBSERVATION HISTORY
- Total Observations: 23
- Most Recent: 2026-06-19
- Key Signals:
- Cloud/hosting classification confirmed (2026-06-14)
- High abuse subnet classification observed (2026-06-05)
- Operator score: Minimal (0.2174)
- Route stability: Not stable
- No persistent malicious behavior detected
---
## NETWORK RELATIONSHIPS
- Total Relationships: 65
- Primary Network: OVH_282347340
- Correlated IPs: 0
- Certificate Matches: 0
---
## RECOMMENDED ACTIONS
Current Risk Level: Moderate (40) โ No immediate action required unless contextual threats emerge.
Firewall Rules (for consideration):
```bash
# iptables
iptables -A INPUT -s 198.244.183.71 -j DROP
# nftables
nft add rule inet filter input ip saddr 198.244.183.71 drop
# nginx
deny 198.244.183.71;
# pfSense
198.244.183.71/32
# Cloudflare WAF
{
"description": "Block 198.244.183.71 โ IPDebrief risk score 40",
"action": "block",
"filter": {"expression": "ip.src eq 198.244.183.71"}
}
# AWS WAF
{
"Addresses": ["198.244.183.71/32"],
"Description": "IPDebrief risk 40"
}
```
Recommendation: No blocking recommended at this time. The IP shows legitimate cloud infrastructure characteristics with no active threat indicators. Monitor for changes in behavior, particularly given the elevated abuse density in the associated /24 subnet.
---
END OF BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk004-san71.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk004-san71.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 17% | 2 | 3 |
| ownership | 17% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 22% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-09 11:33:50 UTC |
| Last Seen | 2026-06-27 15:27:15 UTC |
| Profile Built | 2026-06-28 09:32:38 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 28 |
Full dossier details are available via our API.