## IP Intelligence Briefing: 198.244.226.226/32
Classification: Moderate Risk | Timestamp: 2024-01-15
Executive Summary
IP address 198.244.226.226 is a cloud compute endpoint hosted by OVH (ASN 16276) in London, England. The IP resolves to legitimate Ahrefs infrastructure (proxy-uk002-san226.ahrefs.net) with moderate risk scoring (50/100). While no direct threat indicators were observed, the subnet exhibits elevated abuse density (0.6641), suggesting shared infrastructure with other potentially compromised endpoints.
Technical Profile
Ownership & Infrastructure:
- ASN: 16276 (OVH SAS)
- Organization: Ahrefs Pte Ltd Dmytro
- RIR: RIPE NCC
- Registration: 2001-02-15 (9,256 days active)
- BGP Prefix: 198.244.128.0/17
- Route Stability: Stable (0 route changes in 30 days)
Geolocation:
- Country: Great Britain (GB)
- Region: England, London
- RTT: 88.2ms average (5 probes)
- DNSSEC: Valid
- IP Reputation: Moderate Risk
Network Role & Services:
- Infrastructure Type: Cloud Compute
- Connection Type: Firewalled / No Services
- Open Ports: None detected
- TLS Certificate: None
- HTTP Services: None
DNS Analysis:
- PTR Record: proxy-uk002-san226.ahrefs.net
- Forward Resolution: Confirmed (ahrefs.net domain)
- Email Authentication: SPF/DMARC not configured on domain
- DNSBL Listings: 2 of 8 total lists
Threat Assessment
Direct Threat Indicators: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Blacklist Count: 0
- Known Campaigns: None
Abuse Context:
- Subnet Classification: High Abuse (198.244.226.226/24)
- Subnet Abuse Density: 0.6641 (66.41% of neighbors flagged)
- Threat Siblings in /24: 170 out of 204 active
- Historical Abuse Density: Varied 0.3906β0.6641 over observation period
Behavioral Observations
30-Day History Analysis:
- Ownership changes: 0
- Threat persistence days: 0
- Threat observation count: 1
- Not persistently malicious
Relationship Network:
- 58 relationships identified
- Primary association: OVH_282347338 network
- Subnet neighbors: 100 analyzed (68 medium risk, 32 low risk)
Recommended Security Actions
Immediate Mitigation:
```bash
# iptables
iptables -A INPUT -s 198.244.226.226 -j DROP
# nftables
nft add rule inet filter input ip saddr 198.244.226.226 drop
# nginx
location / { deny 198.244.226.226; }
```
Cloud Platform Rules:
- Cloudflare WAF: Block 198.244.226.226 (risk score 50)
- AWS WAF: Add 198.244.226.226/32 to IP set
- pfSense: Add 198.244.226.226/32 to block list
Analyst Notes
This IP resolves to legitimate Ahrefs proxy infrastructure. However, the high-abuse subnet classification warrants monitoring. The 66% abuse density within the /24 indicates significant peer risk. While no direct threat indicators are present, the shared hosting environment suggests potential lateral movement risk if any neighboring IPs are compromised. Recommend monitoring for:
- Port scanning activity from this subnet
- Unauthorized DNS queries
- Traffic patterns inconsistent with Ahrefs proxy behavior
- Correlation with other flagged IPs in the OVH_282347338 network
Threat Level: LOWβMODERATE (context-dependent based on organizational exposure)
---
*Intelligence generated by IPDebrief. Recommendations should be combined with additional signals before action.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | β |
| CIDR Block | 198.244.128.0/17 |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | proxy-uk002-san226.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk002-san226.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 27% | 2 | 3 |
| services | 24% | 2 | 3 |
| ownership | 35% | 3 | 6 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 30% | 12 | 22 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-17 03:08:16 UTC |
| Last Seen | 2026-06-28 04:25:30 UTC |
| Profile Built | 2026-06-28 22:30:40 UTC |
| Data Freshness | Live |
| Signal Types | 27 |
| Total Observations | 34 |
Full dossier details are available via our API.