## IP Intelligence Briefing: 198.244.226.208/32
Date: 2026-06-28
Classification: Moderate Risk - Cloud Infrastructure
Executive Summary
IP 198.244.226.208 is a cloud-hosted infrastructure endpoint associated with Ahrefs Pte Ltd Dmytro (AS16276), operated by OVH SAS. The IP exhibits moderate risk (score: 50) with evidence of hosting activity and cloud infrastructure deployment. No active threat indicators detected at present.
---
Technical Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 50 (Moderate Risk) |
| **ASN** | 16276 (OVH SAS) |
| **Organization** | Ahrefs Pte Ltd Dmytro |
| **Location** | London, England, GB |
| **Infrastructure** | Cloud Compute / Hosting |
| **DNS PTR** | proxy-uk002-san208.ahrefs.net |
| **Forward Hostname** | proxy-uk002-san208.ahrefs.net |
| **Domain** | ahrefs.net |
| **Open Ports** | None detected |
---
Threat Assessment
Current Risk Level: Moderate
- Threat Indicators: No active threat indicators identified
- Blacklist Status: Listed on 2 of 8 DNSBL sources
- Known Campaigns: None detected
- Tor/Proxy: Not identified as Tor exit node, proxy, or VPN
- Infrastructure Classification: Cloud hosting environment
Key Observations:
- No services detected on open ports; firewall appears active
- PTR record resolves to a proxy hostname within the ahrefs.net domain
- Hosted domains count: 0 (forward resolution confirmed)
---
Neighborhood Analysis
Subnet: 198.244.226.0/24
- Abuse Density: 0.6484 (High Abuse Classification)
- Total Siblings: 256
- Active Siblings: 204
- Threat Siblings: 166
Risk Distribution in /24:
- High Risk: 0
- Medium Risk: 72
- Low Risk: 28
The subnet exhibits elevated abuse density with significant threat activity. The target IP shares network context with 166 identified threat siblings, suggesting potential for coordinated or adjacent malicious activity.
---
Historical Signals (24 Observations)
Recent signal history indicates:
- June 19, 2026: Subnet abuse classification confirmed (high_abuse, 0.6484 density)
- June 19, 2026: Routing signals from AS16276 OVH SAS
- June 28, 2026: Operator score 0.2174 (Minimal risk classification)
- Geolocation: Consistent GB placement with plausible geo data
No evidence of escalating threat persistence or behavioral changes indicating active malicious campaigns.
---
Recommendations for SOC Analysts
1. Monitoring Priority: Medium โ Monitor for outbound connections from this IP; no immediate blocking required
2. Network Context: Be aware of subnet-level abuse density; consider correlating with 166 threat siblings if investigating lateral movement
3. Firewall Rules: No specific block recommendations; allow-list consideration depends on organization's relationship with Ahrefs
4. Threat Intelligence: No active IoCs requiring immediate action; maintain passive monitoring
Actionable Rule: No immediate firewall action required. Monitor for behavioral anomalies given neighborhood abuse context.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk002-san208.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk002-san208.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 20% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 27% | 1 | 3 |
| geolocation | 31% | 2 | 3 |
| Overall | 23% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-14 19:28:42 UTC |
| Last Seen | 2026-06-28 01:22:26 UTC |
| Profile Built | 2026-06-29 01:27:48 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 27 |
Full dossier details are available via our API.