IP INTELLIGENCE BRIEFING
Target: 198.244.226.108/32
Classification: Moderate Risk | Generated: Current
---
EXECUTIVE SUMMARY
IP 198.244.226.108 is a cloud compute resource operated by OVH (ASN 16276) hosting Ahrefs infrastructure (ahrefs.net). The IP presents moderate risk (score: 40) driven primarily by high-abuse neighborhood density rather than direct malicious indicators. No active threats, campaigns, or persistent malicious behavior observed.
OWNERSHIP & GEOLOCATION
- Organization: Ahrefs Pte Ltd Dmytro
- ASN: 16276 (OVH)
- Location: London, England, GB
- Infrastructure: CloudCompute (OVH)
- Network Block: 198.244.128.0/17 (BGP stable, origin ASN 16276)
NETWORK CHARACTERISTICS
- DNS: proxy-uk002-san108.ahrefs.net (ahrefs.net)
- Services: No open ports detected; firewall/no services observed
- Routing: Stable route, not a MOAS
- DNSBL: Listed on 1 of 8 total lists (dnsblListedCount: 1)
THREAT INDICATORS
- Risk Score: 40 (Moderate)
- Abuse Confidence: Not elevated
- Known Attacker: No
- Spam Source: No
- Tor Exit/Proxy: No
- Campaign Matches: 0
- Threat Feeds: None
NEIGHBORHOOD ANALYSIS
- Subnet: 198.244.226.0/24
- Abuse Density: 0.6484 (high_abuse classification)
- Active Siblings: 199 of 256 total
- Threat Siblings: 166
- Risk Distribution: Medium (100% of sampled neighbors)
HISTORICAL OBSERVATIONS
- Observations: 25 signals tracked
- Route Stability: Consistent (0 changes in 30 days)
- Ownership Changes: 0
- Threat Persistence: 0 days observed
- Behavioral Status: Not persistently malicious
---
INTELLIGENCE ASSESSMENT
The target IP operates as part of Ahrefs proxy infrastructure on OVH cloud compute. Risk is elevated by neighborhood abuse patterns common in shared cloud environments rather than IP-specific malicious activity. The 198.244.226.0/24 subnet shows high abuse density with 64.84% abuse rate and 166 threat siblings, indicating a potentially compromised or misused hosting block.
RECOMMENDED ACTIONS
- Block: Consider blocking at perimeter firewall (risk score 40, neighborhood abuse)
- Monitor: Track for any changes in threat indicators
- Context: Legitimate Ahrefs infrastructure; false positives possible if abuse originates from nearby IPs
FIREWALL RULES (For Immediate Action)
- iptables: `iptables -A INPUT -s 198.244.226.108 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 198.244.226.108 drop`
- Cloudflare WAF: Block IP with expression `ip.src eq 198.244.226.108`
- AWS WAF: Add to deny list `198.244.226.108/32`
---
SOURCES: IPDebrief Intelligence Platform
CONFIDENCE: High (25 historical observations, multiple signal types)
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | 198.244.128.0/17 |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk002-san108.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk002-san108.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 33% | 2 | 3 |
| services | 12% | 2 | 2 |
| ownership | 37% | 3 | 6 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 29% | 12 | 21 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-19 23:49:34 UTC |
| Last Seen | 2026-06-28 10:31:51 UTC |
| Profile Built | 2026-06-29 04:36:15 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 32 |
Full dossier details are available via our API.