# IP INTELLIGENCE BRIEFING
Target: 198.244.240.105/32
Date: 2026-06-20
Classification: Moderate Risk - High Neighborhood Risk
---
## EXECUTIVE SUMMARY
IP 198.244.240.105 presents a moderate-risk profile (40/100) with ownership tied to legitimate infrastructure provider OVH (ASN 16276). However, the associated /24 subnet exhibits elevated abuse characteristics with 76.95% abuse density and 197 threat-sibling IPs identified. While the IP resolves to legitimate Ahrefs infrastructure (proxy-uk006-san105.ahrefs.net), network-level threat activity warrants defensive consideration.
---
## OWNERSHIP & NETWORK CLASSIFICATION
- Organization: Ahrefs Pte Ltd Dmytro (OVH provider)
- ASN: 16276
- Location: London, England, GB (Europe/London)
- Infrastructure Type: CloudCompute/Hosting
- Network Role: Firewalled/No Services Exposed
- Registration: ARIN RIR registry
---
## THREAT INDICATORS
- Risk Score: 40/100 (Moderate)
- Abuse Confidence: Not elevated at IP level
- Known Campaigns: None identified
- Tor Exit Node: False
- Known Attacker: False
- Spam Source: False
- Blacklist Count: 0
- DNSBL Listed: 1 of 8 total lists
---
## NEIGHBORHOOD ANALYSIS
The /24 subnet (198.244.240.0/24) shows concerning characteristics:
- Abuse Density: 0.7695 (High)
- Threat Siblings: 197 of 256 IPs classified as threats
- Active Siblings: 163
- Inherited Risk: 30/100
This indicates the subnet is being leveraged for malicious activity despite legitimate enterprise ownership.
---
## OBSERVATION HISTORY
Recent observations (June 2026) maintain consistent network classification. Historical signals show:
- Stable geolocation attribution (London)
- Persistent hosting classification
- Recent threat persistence metrics: 0 days
---
## RELATIONSHIPS
- Network Affiliations: Multiple relationships to OVH_282347342 network
- DNS Records: proxy-uk006-san105.ahrefs.net (forward confirmed)
- BGP Prefix: 198.244.128.0/17
---
## RECOMMENDED ACTIONS
Immediate:
```bash
# iptables
iptables -A INPUT -s 198.244.240.105 -j DROP
# nftables
nft add rule inet filter input ip saddr 198.244.240.105 drop
```
Cloud/WAF:
- Cloudflare WAF: Block IP with risk score 40
- AWS WAF: Add to allow/block list
- pfSense: Apply block rule
Note: Subnet-level blocking (198.244.240.0/24) may be warranted given high neighborhood abuse density, though this may impact legitimate Ahrefs traffic.
---
## INTELLIGENCE ASSESSMENT
This IP represents a legitimate enterprise infrastructure address operating within a high-abuse neighborhood. The moderate risk score is not driven by the IP itself but by its subnet context. SOC analysts should monitor for traffic patterns that may indicate compromise of legitimate infrastructure, and consider whether blocking the entire /24 subnet aligns with business tolerance for potential false positives against Ahrefs services.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk006-san105.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk006-san105.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 23% | 9 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-20 05:44:20 UTC |
| Last Seen | 2026-06-28 11:03:13 UTC |
| Profile Built | 2026-06-29 05:09:47 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 24 |
Full dossier details are available via our API.