## IP INTELLIGENCE BRIEFING: 198.244.226.250
Classification: MODERATE RISK / HIGH-ABUSE SUBNET
Date Generated: 2026-06-20
Analysis ID: IP-198.244.226.250-20260620
EXECUTIVE SUMMARY
IP 198.244.226.250 is a cloud computing infrastructure address operated by OVH (ASN 16276) for organization Ahrefs Pte Ltd Dmytro. The IP is located in London, England and is associated with a high-abuse density subnet (198.244.226.0/24) with 64.84% abuse classification. Risk score is moderate (40/100) with no active threat indicators, but contextual risk is elevated due to neighborhood context and routing instability.
OWNERSHIP & INFRASTRUCTURE
- ASN: 16276 (OVH)
- Organization: Ahrefs Pte Ltd Dmytro
- RIR: ARIN
- Geolocation: London, England, GB (validated, 473.7km from reference point)
- Infrastructure Type: Cloud Compute (Hosting)
- Network Role: Firewall / No Services (no open ports detected)
- DNS Record: proxy-uk002-san250.ahrefs.net
THREAT INDICATORS
- Risk Score: 40 (Moderate Risk)
- Known Threat Feeds: None
- Known Campaigns: None
- Blacklist Status: 0 blacklist entries
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- DNSBL Status: Listed on 1 of 8 threat feeds
NETWORK CONTEXT & RISK ELEVATORS
- Subnet Abuse Density: 0.6484 (High Abuse Classification)
- Threat Siblings in /24: 166 out of 256 total IPs
- Active Siblings: 199
- Inherited Risk: 25 (from neighborhood context)
- Route Stability: False (routing instability detected)
- Operator Score: 0.2174 (Minimal)
- BGP Prefix: 198.244.128.0/17
OBSERVATION HISTORY
- Total Observations: 23 signals
- Recent Activity: 2026-06-15 to 2026-06-20
- Persistence: Not persistently malicious
- Threat Observation Count: 1
- Geolocation Validation: Plausible (minimum possible RTT: 9.5ms)
NETWORK RELATIONSHIPS
- Same Network Associations: 36 relationships to OVH infrastructure (OVH_282347338)
- Control Plane: Origin ASN 16276, RPKI state undetermined
SECURITY RECOMMENDATIONS
Based on the IP's profile:
- Recommended Action: Monitor / Block based on organizational policy
- Rationale: Moderate risk score combined with high-abuse subnet context warrants defensive monitoring
- Firewall Rule: Consider rate limiting if outbound connections are permitted to this IP
- Geolocation Filter: London, GB (consider if geo-filtering is in use)
ANALYST NOTES
This IP is part of OVH cloud hosting infrastructure for Ahrefs. While the IP itself shows no active threat indicators, it resides in a subnet with 64.84% abuse density. The route instability (isRouteStable: false) and minimal operator score suggest dynamic infrastructure typical of cloud hosting. No immediate threat indicators present, but contextual risk from neighborhood context should inform security policy decisions.
END OF BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk002-san250.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk002-san250.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-19 03:35:40 UTC |
| Last Seen | 2026-06-28 08:22:03 UTC |
| Profile Built | 2026-06-29 02:26:05 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 27 |
Full dossier details are available via our API.