# IP Intelligence Briefing: 198.244.226.244
## Executive Summary
IP address 198.244.226.244 presents a Moderate Risk profile (risk score: 40) within a high-abuse-density subnet (abuse density: 0.6133). The IP is hosted by OVH in the London region, UK, and is associated with Ahrefs Pte Ltd Dmytro. While no active threat indicators were identified, the IP resides in a subnet with 157 confirmed threat siblings, warranting defensive monitoring.
## Network Classification
- Provider: OVH (ASN: 16276)
- Infrastructure Type: Cloud Compute / Hosting
- Geolocation: GB (England, London) โ inferred with 28% confidence
- BGP Prefix: 198.244.128.0/17
- Subnet: 198.244.226.0/24 (high_abuse classification)
## Risk Assessment
| Metric | Value |
|---|---|
| Risk Score | 40 (Moderate) |
| Provider Score | 0 |
| Authority Score | 0 |
| Stability Score | 0 |
| DNSBL Listings | 1 of 8 |
| Abuse Confidence | Not reported |
The IP shows no direct threat indicators: not classified as a known attacker, spam source, Tor exit node, or VPN/proxy. However, the subnet-level abuse density (0.6133) and 157 threat siblings indicate elevated neighborhood risk.
## DNS & Services
- PTR Hostname: proxy-uk002-san244.ahrefs.net
- Forward Resolved Domain: ahrefs.net
- Open Ports: None detected
- Services: No open services (firewalled/no services detected)
- TLS Certificate: None
- HTTP Services: None
## Historical Signals (25 Observations)
Recent observations (as of 2026-06-14) indicate:
- Consistent cloud hosting classification (OVH)
- Abuse density signals persisting at 0.6133
- Geographic inference consistently pointing to GB region
- No changes in infrastructure type or provider
## Related Entities
- Network: OVH_282347338 (198.244.128.0/17)
- Related IPs: 57 network relationships identified
- Subnet Risk: 166 active siblings, 157 threat siblings in /24
## Recommended Actions
Based on the moderate risk profile and high-abuse neighborhood context, the following firewall rules are recommended:
```bash
# iptables
iptables -A INPUT -s 198.244.226.244 -j DROP
# nftables
nft add rule inet filter input ip saddr 198.244.226.244 drop
# nginx
deny 198.244.226.244;
# pfSense
198.244.226.244/32
# Cloudflare WAF
action: block
expression: ip.src eq 198.244.226.244
# AWS WAF
Addresses: 198.244.226.244/32
Description: IPDebrief risk 40
```
## Intelligence Conclusion
This IP warrants monitoring with defensive blocking due to its location in a high-abuse-density subnet. While the individual IP shows no direct malicious indicators, the subnet context (157 threat siblings) suggests potential lateral risk. Consider blocking at the perimeter with continued monitoring for any behavioral changes.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk002-san244.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk002-san244.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 24% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 27% | 1 | 3 |
| geolocation | 31% | 2 | 3 |
| Overall | 24% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-10 10:13:37 UTC |
| Last Seen | 2026-06-27 17:26:45 UTC |
| Profile Built | 2026-06-28 11:32:26 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 28 |
Full dossier details are available via our API.