# IP INTELLIGENCE BRIEFING
## Target: 198.244.226.76/32
Classification: Moderate Risk Cloud Infrastructure Address
Date Generated: 2026-06-19
---
EXECUTIVE SUMMARY
IP address 198.244.226.76 resolves to cloud infrastructure operated by Ahrefs Pte Ltd Dmytro under OVH ASN 16276. While the address itself shows moderate risk (score: 40), it resides within a high-abuse-density subnet (198.244.226.0/24) with 64.84% abuse density and 166 malicious sibling IPs. The address is associated with legitimate Ahrefs infrastructure but exhibits conflicting reputation signals requiring defensive monitoring.
---
OWNERSHIP & GEOLOCATION
- Organization: Ahrefs Pte Ltd Dmytro
- ASN: 16276 (OVH SAS)
- Location: London, England, GB
- Infrastructure Type: CloudCompute / Hosting
- CIDR Block: 198.244.128.0/17
- DNS PTR: proxy-uk002-san76.ahrefs.net
- Registration: ARIN registry
---
THREAT ASSESSMENT
| Metric | Value |
|---|---|
| Risk Score | 40 (Moderate) |
| Provider Risk | 0 |
| Authority Risk | 0 |
| DNSBL Listed | 1 of 8 lists |
| Known Attacker | No |
| Spam Source | No |
| Tor Exit Node | No |
| Campaign Match | None |
Critical Finding: Despite the IP's association with Ahrefs infrastructure, the parent subnet (198.244.226.0/24) shows concerning abuse metrics:
- Abuse Density: 0.6484 (64.84%)
- Threat Siblings: 166 of 256 IPs in subnet
- Inherited Risk Score: 25
- Classification: High Abuse
---
OBSERVATION HISTORY (Last 21 Signals)
Recent intelligence indicates:
- 2026-06-19: Multiple threat signals detected from AlienVault OTX (4 pulses)
- 2026-06-19: Subnet abuse density confirmed at high threshold
- 2026-06-14: Single threat observation recorded
- Threat Persistence: Not persistently malicious
- Observation Count: 1 documented threat event
---
NETWORK RELATIONSHIPS
- Total Relationships: 53
- Primary Network Entity: OVH_282347338 (repeated associations)
- Network Classification: Same Network relationships dominate relationship graph
---
RECOMMENDED ACTIONS
Priority: Monitor
1. Firewall Rules: No specific block recommendations due to legitimate Ahrefs infrastructure association. Monitor for suspicious outbound connections.
2. SOC Monitoring:
- Alert on unusual traffic patterns from this IP
- Monitor for C2 beaconing or data exfiltration attempts
- Track correlation with other subnet addresses (198.244.226.x)
3. Threat Hunting:
- Investigate why this Ahrefs infrastructure IP shows threat indicators
- Check for compromise of legitimate Ahrefs cloud hosting
- Review for potential abuse of cloud infrastructure for malicious purposes
4. Blocklist Status: IP listed on 1 of 8 DNSBLs. Verify listing rationale before implementing blocking.
---
INTELLIGENCE NOTES
This IP represents a risk-reputation conflict: legitimate Ahrefs cloud infrastructure hosting compromised alongside potentially malicious traffic in the same subnet. The high abuse density of the parent subnet suggests either:
- Compromise of legitimate infrastructure
- Aggressive abuse of cloud hosting services
- Need for enhanced monitoring on all 198.244.226.x addresses
Recommendation: Implement traffic analysis rules rather than blocking, given legitimate business use cases for Ahrefs infrastructure in this subnet.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk002-san76.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk002-san76.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 22% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-14 01:09:28 UTC |
| Last Seen | 2026-06-28 00:06:14 UTC |
| Profile Built | 2026-06-28 18:11:43 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 25 |
Full dossier details are available via our API.