IP Intelligence Briefing: 198.244.226.216
Date: 2026-06-14
---
**1. IP Profile**
- Risk Score: 40 (Moderate Risk)
- Owner: Ahrefs Pte Ltd (AS16276, OVH provider)
- Geolocation: London, England, GB (ARIN-registered)
- Network Role: Cloud compute resource (OVH hosting, no residential/mobile attributes)
- Threat Indicators: No malicious activity detected (no blacklists, spam, or campaigns).
---
**2. Observation History**
- Latest Activity: 2026-06-14 (Minimal risk signal, 0.2174 operator score).
- Historical Trends: Single observation; no persistent malicious behavior.
- Geolocation Validity: Plausible (473.7 km from claimed location, 89 ms avg RTT).
---
**3. Network Relationships**
- Linked Entities:
- OVH Network (AS16276): Subnet 198.244.128.0/17, high abuse density (0.5078).
- Domains: Resolves to `ahrefs.net` (no email auth records).
- Subnet Context:
- /24 Subnet (198.244.226.0/24): 100 total IPs, 85 medium/high risk neighbors.
- Abuse Density: 50.78% (high-risk sibling IPs: 130/256).
---
**4. Threat Context**
- No Direct Malicious Indicators: No DNS, TLS, or service anomalies.
- Subnet Risk: High abuse density suggests potential lateral movement or compromised neighbors.
- Hosting Provider: OVHβs cloud infrastructure may be a target for attacks.
---
**5. Recommended Actions**
- Monitor Subnet: Investigate high-risk neighbors (e.g., 198.244.226.1, 198.244.226.2).
- Block IP Temporarily: If suspicious activity is detected, apply firewall rules via:
- `iptables -A INPUT -s 198.244.226.216 -j DROP`
- Cloudflare/AWS WAF rules for outbound traffic.
- Verify Ownership: Confirm Ahrefsβ compliance with DNSSEC and CAA records.
---
Conclusion: While the IP itself is not malicious, its subnet exhibits high abuse density. SOC teams should prioritize monitoring and isolating this subnet to mitigate potential lateral threats.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | proxy-uk002-san216.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk002-san216.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 17% | 2 | 3 |
| ownership | 17% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 22% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-12 15:47:39 UTC |
| Last Seen | 2026-06-27 21:38:18 UTC |
| Profile Built | 2026-06-28 15:43:08 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 27 |
Full dossier details are available via our API.