IP INTELLIGENCE BRIEFING: 198.244.240.103/32
Classification: MODERATE RISK โ HOSTING INFRASTRUCTURE WITH HIGH-ABUSE SUBNET CONTEXT
---
EXECUTIVE SUMMARY
IP 198.244.240.103 is a cloud-hosting address in the OVH network with a moderate risk score of 40. The IP resides within a /24 subnet classified as "high_abuse" (0.832 abuse density), containing 213 identified threat siblings out of 256 total. No direct malicious activity indicators were observed on this specific IP.
---
OWNERSHIP & INFRASTRUCTURE
- Organization: Ahrefs Pte Ltd Dmytro (ASN 16276)
- Provider: OVH Cloud (Infrastructure Type: CloudCompute)
- Location: London, England, GB
- DNS PTR: proxy-uk006-san103.ahrefs.net
- Network Role: Hosting/CloudCompute with firewall/no services detected
---
THREAT INDICATORS & OBSERVATIONS
- Risk Score: 40 (Moderate)
- Abuse Confidence: 0 (no active threat indicators)
- Blacklist Status: 1 DNSBL listing (of 8 total lists monitored)
- Known Campaigns: None
- Known Attacker/Spam Source/Tor Exit: False
- Service Status: Firewall/no services detected
---
NEIGHBORHOOD ANALYSIS
The /24 subnet (198.244.240.0/24) exhibits elevated abuse activity:
- Total Subnet IPs: 256
- Active Siblings: 199
- Threat Siblings: 213
- Risk Distribution: 50 medium, 50 low risk (neighborhood lookup)
- Inherited Risk: 33
---
HISTORICAL SIGNALS
25 observations tracked. Most recent activity recorded 2026-06-28. Historical data shows consistent classification as cloud hosting infrastructure (OVH) with minimal changes in ownership or threat persistence. No escalation patterns observed.
---
RELATED ENTITIES
36 relationships identified, primarily same-network associations (OVH_282347342). No certificate matches or correlated IPs beyond network-level relationships.
---
RECOMMENDED ACTIONS
Based on moderate risk score and high-abuse subnet context:
Firewall Rules:
- `iptables -A INPUT -s 198.244.240.103 -j DROP`
- `nft add rule inet filter input ip saddr 198.244.240.103 drop`
- `nginx deny 198.244.240.103;`
WAF Integration:
- Cloudflare WAF: Block IP
- AWS WAF: Add 198.244.240.103/32 to deny list
---
ASSESSMENT
This IP is associated with Ahrefs hosting infrastructure on OVH cloud. While no direct threat indicators are present, the subnet context (0.832 abuse density, 213 threat siblings) warrants monitoring. Recommend blocking at edge firewall due to neighborhood risk profile. No immediate evidence of malicious activity originating from this specific IP.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk006-san103.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk006-san103.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 24% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-19 21:39:50 UTC |
| Last Seen | 2026-06-28 09:51:56 UTC |
| Profile Built | 2026-06-29 03:56:09 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 25 |
Full dossier details are available via our API.