# Intelligence Briefing: 198.244.226.229/32
## Executive Summary
IP address 198.244.226.229 presents moderate risk (score: 40) with elevated neighborhood abuse density. The address is hosted on OVH infrastructure (ASN 16276) under organization "Ahrefs Pte Ltd Dmytro" with geolocation indicators pointing to London, England, though geolocation consensus remains unresolved. Recent observation history confirms active threat indicators via AlienVault OTX.
## Risk Assessment
- Overall Risk Score: 40 (Moderate)
- Abuse Confidence: Evident through neighborhood classification
- Network Classification: Cloud compute infrastructure with hosting services
- Threat Indicators: Multiple threat pulses detected in recent observations; 1 DNSBL listing among 8 total lists
- Persistence: Not persistently malicious; ownership and threat observations show 0 days of persistent activity
## Technical Profile
- ASN: 16276 (OVH SAS)
- BGP Prefix: 198.244.128.0/17
- Network Role: Cloud Compute, Hosting
- DNS Resolution: proxy-uk002-san229.ahrefs.net (ahrefs.net domain)
- Services: No open ports; firewall appears active
- Route Stability: Route flagged as unstable
## Neighborhood Analysis
The /24 subnet (198.244.226.0/24) exhibits significant abuse activity:
- Abuse Density: 0.5977 (high_abuse classification)
- Total Siblings: 256 addresses
- Active Siblings: 144
- Threat Siblings: 153
- Risk Distribution: 100 medium-risk neighbors; 0 high/low risk
- Inherited Risk Score: 23
The high concentration of threat siblings indicates this IP resides in a subnet with elevated malicious activity rates.
## Observation History
Analysis of 22 historical observations reveals:
- Recent Threat Activity: June 2026 observations flagged threats via AlienVault OTX with confidence scores of 0.60-0.85
- Threat Persistence: 1 total threat observation recorded
- Operator Score: 0.2174 (Minimal operator-level risk)
- DNSSEC Status: Valid
## Relationship Graph
38 relationships identified, all categorized as "Same Network" (OVH_282347338), indicating the IP is part of a broader OVH infrastructure network with associated entities.
## Recommended Actions
Based on risk profile and neighborhood context, the following firewall rules are recommended:
- iptables: `iptables -A INPUT -s 198.244.226.229 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 198.244.226.229 drop`
- nginx: `deny 198.244.226.229;`
- pfSense: `198.244.226.229/32`
- Cloudflare WAF: Block with expression `ip.src eq 198.244.226.229`
- AWS WAF: Address `198.244.226.229/32` with description "IPDebrief risk 40"
## Intelligence Notes
The IP's association with a high-abuse-density subnet suggests potential use within compromised infrastructure. While individual risk scoring is moderate (40), the neighborhood context warrants defensive blocking. The DNS hostname pattern (proxy-uk002-san229) suggests this may be part of a proxy or redirect service infrastructure. SOC teams should monitor for lateral activity within the 198.244.226.0/24 subnet and correlate with other threat intelligence sources.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk002-san229.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk002-san229.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 24% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-21 14:56:57 UTC |
| Last Seen | 2026-06-28 13:58:34 UTC |
| Profile Built | 2026-06-29 02:04:26 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.