## IP Intelligence Briefing: 198.244.226.140
Classification: Moderate Risk / Cloud Infrastructure
Executive Summary
IP 198.244.226.140 is a cloud-compute host operated by OVH (ASN 16276) in London, England, with ownership attributed to Ahrefs Pte Ltd. The IP presents a moderate risk profile (score: 50) with no open services detected, though it resides in a high-abuse density neighborhood and carries multiple DNSBL listings.
Infrastructure Profile
- Provider: OVH (AS16276)
- Infrastructure Type: CloudCompute / Hosting
- Geolocation: London, England, GB (Europe/London timezone)
- BGP Prefix: 198.244.128.0/17
- PTR Hostname: proxy-uk002-san140.ahrefs.net
- DNS Domain: ahrefs.net
- Service Status: Firewalled / No Services (no open ports detected)
Risk Assessment
- Overall Risk Score: 50 (Moderate)
- Abuse Confidence: Listed on 8 DNSBLs with 2 active listings
- Operator Score: 0.2174 (Minimal)
- Route Stability: Unstable (routeChanges30d: 0)
- Known Threat Indicators: None detected
- Tor Exit / Proxy / CDN: Negative
Neighborhood Context
- Subnet: 198.244.226.0/24
- Abuse Density: 0.6602 (High Abuse Classification)
- Total Siblings: 256 (199 active)
- Threat Siblings: 169
- Inherited Risk Score: 26
- Notable Neighbors: Multiple medium-to-high risk IPs in adjacent ranges
Observation History
23 historical observations recorded. Recent signals (2026-06-20) confirm:
- OVH hosting infrastructure classification
- Cloud infrastructure designation
- Minimal operator risk score
- Threat presence detected in broader network context
Relationship Graph
36 identified relationships, predominantly network-level associations to OVH infrastructure (OVH_282347338). No direct organizational or certificate relationships beyond hosting provider.
Recommended Actions
Based on the risk profile and neighborhood context:
1. Monitor - IP shows legitimate enterprise association (Ahrefs) but requires ongoing monitoring due to high-abuse neighborhood
2. DNSBL Review - Investigate 8 DNSBL listings; 2 currently active
3. Traffic Analysis - No open ports detected; validate legitimate traffic patterns
4. Block Decision - Context-dependent. Legitimate ownership suggests allow with monitoring, but neighborhood abuse warrants scrutiny
Conclusion
This IP represents cloud hosting infrastructure for a legitimate SEO provider (Ahrefs) but operates within a high-abuse subnet. The absence of open services and clear enterprise ownership suggests benign intent, yet the elevated neighborhood abuse density warrants continued traffic monitoring and DNSBL investigation. No immediate blocking recommended without correlation of malicious traffic patterns.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk002-san140.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk002-san140.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 24% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-22 03:09:21 UTC |
| Last Seen | 2026-06-28 17:21:03 UTC |
| Profile Built | 2026-06-29 05:23:31 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 26 |
Full dossier details are available via our API.