IP INTELLIGENCE BRIEFING
Target IP: 198.244.226.91/32
Classification: Moderate Risk (Score: 40/100)
Reporting Date: 2026-06-18
---
EXECUTIVE SUMMARY
IP 198.244.226.91 is a cloud infrastructure endpoint associated with OVH (ASN 16276) and registered under Ahrefs Pte Ltd Dmytro. The IP resolves to proxy-uk002-san91.ahrefs.net with geolocation in London, England. While the IP itself shows no direct malicious indicators, its /24 subnet (198.244.226.0/24) exhibits high abuse density (0.6602) with 169 of 256 siblings flagged as threats. No open services were detected; the endpoint is firewalled.
---
OWNERSHIP AND NETWORK ATTRIBUTES
- Provider: OVH SAS (Cloud Infrastructure)
- Organization: Ahrefs Pte Ltd Dmytro
- ASN: 16276 (OVH)
- BGP Prefix: 198.244.128.0/17
- Geolocation: London, England, GB (RTT: 88-112ms)
- DNS Resolution: proxy-uk002-san91.ahrefs.net (ahrefs.net)
- Infrastructure Type: CloudCompute
- Connection State: Firewalled / No Services
---
THREAT INDICATORS
- Reputation: Moderate Risk (Score: 40)
- Known Campaigns: None identified
- Threat Feeds: Not listed
- Blacklist Status: Listed on 1 of 8 DNSBLs
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Campaign Likelihood: None
---
SUBNET CONTEXT (198.244.226.0/24)
- Abuse Density: 0.6602 (High Abuse Classification)
- Total Siblings: 256
- Active Siblings: 202
- Threat Siblings: 169
- Risk Distribution: 100 medium-risk IPs, 0 high-risk, 0 low-risk
- Inherited Risk Score: 26
---
OBSERVATION HISTORY
24 observations recorded from 2026-06-14 through 2026-06-18. Consistent patterns observed:
- Geolocation signals: GB (London region) with 473.7km distance from claimed coordinates
- RTT measurements: Average 95.8ms, minimum 88ms
- Subnet abuse density: 0.6602 (stable)
- Operator score: 0.2174 (Minimal)
- No ownership changes detected
- Not persistently malicious
---
RELATIONSHIPS
Primary relationship: Same Network (OVH_282347338) with 52 relationship records. No certificate or hostname relationships beyond DNS resolution.
---
SECURITY RECOMMENDATIONS
Recommended Action: Block or monitor based on risk tolerance. The subnet's high abuse density warrants consideration for defensive blocking.
Firewall Rules:
- iptables: `iptables -A INPUT -s 198.244.226.91 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 198.244.226.91 drop`
- nginx: `deny 198.244.226.91;`
- pfSense: `198.244.226.91/32`
- Cloudflare WAF: Block with expression `ip.src eq 198.244.226.91`
- AWS WAF: Add address `198.244.226.91/32` with description "IPDebrief risk 40"
Risk Assessment: The IP is associated with legitimate infrastructure (Ahrefs) but operates within a high-abuse cloud subnet. Monitoring or blocking is recommended based on organizational threat tolerance. The lack of open services reduces immediate exploitation risk, but the subnet context suggests potential for abuse by neighboring endpoints.
---
END OF BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk002-san91.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk002-san91.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 20% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 23% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:06 UTC |
| Last Seen | 2026-06-27 02:46:20 UTC |
| Profile Built | 2026-06-27 20:53:07 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 28 |
Full dossier details are available via our API.