# IP Intelligence Briefing: 198.244.226.210
## Executive Summary
IP address 198.244.226.210 is a moderate-risk (score: 40) host located in London, England, operating under OVH infrastructure (ASN: 16276) for organization Ahrefs Pte Ltd Dmytro. The IP resolves to proxy-uk002-san210.ahrefs.net and is classified as hosting infrastructure with no open services detected. While the IP itself shows no active threat indicators, its /24 neighborhood exhibits elevated abuse density (0.6484) with 166 threat-sibling IPs identified.
## Network Profile
- IP Address: 198.244.226.210/32
- Risk Score: 40 (Moderate Risk)
- ASN: 16276 (OVH)
- Organization: Ahrefs Pte Ltd Dmytro
- Geolocation: London, England, GB (confidence: 0.28, accuracy: 750km radius)
- DNS: proxy-uk002-san210.ahrefs.net (ahrefs.net)
- Network Classification: Hosting infrastructure (CloudCompute), firewalled with no open ports
- BGP Prefix: 198.244.128.0/17
- Route Stability: Stable (no route changes in 30 days)
## Threat Assessment
Current threat indicators show no active malicious activity:
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Blacklist Count: 0
- Known Campaigns: None detected
- Threat Feeds: None matched
- DNSBL Listings: 1 out of 8 total lists
The IP's control plane shows operator score of 0.4783 (Basic) with RPKI state unvalidated.
## Neighborhood Analysis
The /24 subnet (198.244.226.0/24) demonstrates elevated risk characteristics:
- Abuse Density: 0.6484 (High Abuse Classification)
- Total Subnet IPs: 256
- Active Siblings: 202
- Threat Siblings: 166
- Risk Distribution: 0 high-risk, 76 medium-risk, 24 low-risk
- Inherited Risk Score: 25
This indicates the subnet hosts a significant concentration of potentially compromised or abused IP addresses.
## Observation History
26 observations recorded with recent signals from June 26, 2026:
- Network classification signals confirm OVH hosting provider with cloud infrastructure
- DNS signals validate ahrefs.net domain association
- Geolocation signals indicate London placement with 0.28 confidence
- Routing signals show stable BGP routing with operator scores 0.34-0.40
## Relationships
48 relationships identified, primarily same-network associations with OVH_282347338, indicating clustering within OVH's network infrastructure.
## Recommended Actions
1. Monitor: Implement enhanced monitoring for this IP and associated subnet due to high neighborhood abuse density
2. Block Threshold: Consider blocking if threat indicators escalate or DNSBL listings increase
3. Context: Legitimate business infrastructure (Ahrefs) but requires vigilance given subnet abuse patterns
4. Geofencing: Evaluate traffic patterns against expected London-based activity profiles
## Intelligence Conclusion
The IP represents legitimate hosting infrastructure with moderate risk due to neighborhood context rather than direct malicious activity. SOC teams should monitor for behavioral changes and threat indicator emergence, particularly given the subnet's elevated abuse density. Current risk profile warrants defensive monitoring rather than immediate blocking.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | 198.244.128.0/17 |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk002-san210.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk002-san210.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 27% | 2 | 3 |
| services | 24% | 2 | 3 |
| ownership | 22% | 3 | 4 |
| reputation | 28% | 1 | 3 |
| geolocation | 31% | 2 | 3 |
| Overall | 27% | 12 | 20 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-11 22:23:33 UTC |
| Last Seen | 2026-06-27 20:35:01 UTC |
| Profile Built | 2026-06-28 14:39:47 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 32 |
Full dossier details are available via our API.