# INTELLIGENCE BRIEFING: 198.244.226.230
## EXECUTIVE SUMMARY
IP 198.244.226.230 is a cloud-hosted endpoint associated with Ahrefs Pte Ltd, operating under OVH infrastructure in London, United Kingdom. While the IP resolves to a legitimate Ahrefs hostname, it resides within a high-abuse subnet exhibiting significant malicious activity. The endpoint carries a moderate risk score of 40 and shows evidence of DNSBL listing.
## NETWORK CLASSIFICATION
- Organization: Ahrefs Pte Ltd Dmytro (ASN 16276)
- Infrastructure Provider: OVH (CloudCompute)
- Geolocation: London, England, GB
- Network Role: Hosting/CloudCompute with Firewall Configuration
- Infrastructure Type: Cloud-hosted, not residential, proxy, or Tor
## RISK ASSESSMENT
- Overall Risk Score: 40 (Moderate Risk)
- Abuse Confidence Score: Not explicitly scored in current profile
- Blacklist Status: Listed on 1 DNSBL out of 8 total lists
- Known Campaigns: None identified
- Tor Exit Node: No
- Known Attacker: No
## NEIGHBORHOOD THREAT ANALYSIS
The IP resides within subnet 198.244.226.0/24, which demonstrates concerning threat patterns:
- Subnet Abuse Density: 0.6133 (High Abuse Classification)
- Active Siblings: 158 out of 256 total IPs
- Threat Siblings: 157 confirmed malicious endpoints
- Inherited Risk: 24 from neighborhood context
- Risk Distribution: All 100 observed neighbors classified as medium risk (score 40-50)
This indicates the subnet is actively abused, with the vast majority of active endpoints flagged as threats.
## NETWORK BEHAVIOR & SERVICES
- Open Ports: None detected
- TLS Certificate: Not detected
- HTTP Services: No active HTTP banner
- DNS PTR: proxy-uk002-san230.ahrefs.net
- Forward Resolution: proxy-uk002-san230.ahrefs.net (ahrefs.net)
- Control Plane: Route unstable, RPKI state not validated, BGP prefix 198.244.128.0/17
## OBSERVATION HISTORY
Historical signals (19 observations) show consistent patterns:
- Recent operator score: 0.2174 (Minimal)
- DNSSEC validation: Present
- CAA records: Active
- Geographic inference: GB with 0.28 confidence
- Subnet-level analysis consistently classified as high_abuse (0.6133 abuse density)
- Ownership stability: No changes recorded
- Threat persistence: No persistent malicious activity detected
## DNS & EMAIL REPUTATION
- Domain: ahrefs.net
- DNS Records: 1 forward resolution count
- Email Authentication: No SPF, DMARC, or TXT records detected
- Forward Confirmation: Not confirmed
## ACTIONABLE INTELLIGENCE
1. Firewall Recommendation: Monitor inbound traffic; the subnet shows elevated abuse density
2. Threat Context: While the IP resolves to legitimate Ahrefs infrastructure, the high-abuse neighborhood suggests potential compromise or policy violations
3. Investigation Priority: Medium - monitor for lateral movement given 157 threat siblings in the same /24
4. Blocking Decision: No immediate block required; moderate risk score (40) with no active threat indicators
5. Monitoring Focus: Watch for changes in DNSBL listing status and subnet-level threat activity
## CONCLUSION
This endpoint represents a moderate-risk asset within a high-abuse network environment. The legitimate Ahrefs domain association provides some credibility, but the neighborhood context warrants continued monitoring. No immediate blocking action is recommended, but SOC teams should track this IP for anomalous behavior and monitor the subnet for coordinated malicious activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk002-san230.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk002-san230.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 20% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-26 19:49:25 UTC |
| Last Seen | 2026-06-29 03:29:17 UTC |
| Profile Built | 2026-06-29 03:33:10 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.