# IP Intelligence Briefing: 198.244.226.148
## Executive Summary
IP address 198.244.226.148 is associated with OVH cloud infrastructure and demonstrates moderate risk characteristics (score: 40). The IP resolves to Ahrefs.net infrastructure and exhibits mixed-to-high abuse patterns within its /24 subnet. Recommended action: Block at perimeter firewall.
## Ownership and Infrastructure
- ASN: 16276 (OVH)
- Organization: Ahrefs Pte Ltd Dmytro
- Geolocation: England, London, GB
- Infrastructure Type: CloudCompute/Hosting
- DNS Resolution: proxy-uk002-san148.ahrefs.net
- Network Classification: Cloud-hosted infrastructure with no open services detected
## Risk Assessment
- Risk Score: 40/100 (Moderate Risk)
- Abuse Confidence: Low (no blacklist hits; 0/8 DNSBL matches)
- Threat Indicators: None identified (not known attacker, not spam source, not Tor exit node)
- Operator Score: 0.2174 (Minimal)
- Route Stability: False (network routing changes detected)
## Subnet Analysis (198.244.226.0/24)
- Abuse Density: 0.7461 (High Abuse Classification)
- Threat Siblings: 191 of 256 total IPs
- Active Siblings: 214
- Risk Distribution: 25 medium-risk, 75 low-risk neighbors
- Inherited Risk: 29 from subnet analysis
## Historical Observations
Analysis of 24 signal observations indicates temporal volatility:
- 2026-06-20: Abuse density 0.7461, classification "high_abuse", inherited risk 29
- 2026-06-28: Abuse density reduced to 0.3906, classification "mixed", inherited risk 15
- Threat Persistence: Single threat observation recorded
## Recommended Actions
Based on risk profile, the following rules are recommended:
Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 198.244.226.148 -j DROP
# nftables
nft add rule inet filter input ip saddr 198.244.226.148 drop
# nginx
deny 198.244.226.148;
# pfSense
198.244.226.148/32
# Cloudflare WAF
{"description":"Block 198.244.226.148 โ IPDebrief risk score 40","action":"block","filter":{"expression":"ip.src eq 198.244.226.148"}}
# AWS WAF
{"Addresses":["198.244.226.148/32"],"Description":"IPDebrief risk 40"}
```
## Intelligence Notes
The IP appears to be part of Ahrefs proxy infrastructure, but the high-abuse classification of its /24 subnet warrants blocking. The IP shows no active malicious indicators in isolation, but the subnet context and route instability suggest elevated risk. SOC teams should correlate any traffic from this IP with known Ahrefs services to avoid false positives on legitimate traffic.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk002-san148.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk002-san148.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 24% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-22 09:12:31 UTC |
| Last Seen | 2026-06-28 18:29:21 UTC |
| Profile Built | 2026-06-29 06:32:03 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 25 |
Full dossier details are available via our API.