# IP Intelligence Briefing: 198.244.240.139
## Executive Summary
IP 198.244.240.139 presents a moderate risk profile (Score: 40/100) associated with legitimate cloud hosting infrastructure operated by OVH on behalf of Ahrefs Pte Ltd. The IP resolves to a hosted proxy endpoint in London, England, with no direct threat indicators. However, the /24 subnet exhibits elevated abuse density (0.8359), requiring contextual monitoring despite the individual IP's benign characteristics.
## Risk Assessment
| Metric | Value | Classification |
|---|---|---|
| Risk Score | 40 | Moderate Risk |
| Reputation | Moderate Risk | Standard |
| Blacklist Count | 0 | Clean |
| Tor Exit Node | No | Verified |
| Known Attacker | No | Verified |
| Spam Source | No | Verified |
## Technical Profile
Ownership & Infrastructure:
- Organization: Ahrefs Pte Ltd Dmytro
- ASN: 16276
- Hosting Provider: OVH
- Infrastructure Type: CloudCompute
- Network Role: Hosting (Firewalled/No Services)
Geolocation:
- Country/Region: GB / England
- City: London
- Coordinates: 55.38°N, -3.44°W (750km accuracy radius)
- Timezone: Europe/London
DNS Resolution:
- PTR Hostname: proxy-uk006-san139.ahrefs.net
- Domain: ahrefs.net
- Forward Resolution: Confirmed (1 hostname)
Control Plane:
- BGP Prefix: 198.244.128.0/17
- Route Stability: Stable
- DNSSEC: Valid
- CAA Records: Present
- DNSBL Status: Listed on 1 of 8 threat lists
## Neighborhood Analysis
The /24 subnet (198.244.240.0/24) demonstrates concerning abuse characteristics:
- Abuse Density: 0.8359 (High Abuse Classification)
- Total Siblings: 256
- Active Siblings: 208
- Threat Siblings: 214
- Inherited Risk Score: 33
Risk Distribution in Subnet:
- High Risk: 0 IPs
- Medium Risk: 15 IPs
- Low Risk: 85 IPs
## Observation History
22 observations recorded with consistent cloud hosting classification. Recent signals confirm:
- Continuous cloud infrastructure presence (OVH)
- DNS activity resolved to ahrefs.net domains
- No emergence of proxy, VPN, or Tor characteristics
- Stable network role assignment over observation period
## Threat Indicators
No active threat indicators detected:
- No known attack campaigns
- No correlated IP activity
- No certificate-based threat matches
- No honeypot hits
## Recommended Security Actions
Despite moderate individual risk, the high-abuse subnet context warrants defensive measures. Implement the following controls:
Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 198.244.240.139 -j DROP
# nftables
nft add rule inet filter input ip saddr 198.244.240.139 drop
# NGINX
deny 198.244.240.139;
# pfSense
198.244.240.139/32
# Cloudflare WAF
{"description":"Block 198.244.240.139 โ IPDebrief risk score 40", "action":"block", "filter":{"expression":"ip.src eq 198.244.240.139"}}
# AWS WAF
{"Addresses":["198.244.240.139/32"], "Description":"IPDebrief risk 40"}
```
## Intelligence Notes
- The IP resolves to a legitimate proxy endpoint for ahrefs.net (SEO/analytics platform)
- No services currently open or listening on the host
- DNSSEC and CAA records indicate proper security posture
- Consider monitoring adjacent IPs in the /24 subnet due to high abuse density
- Recommended to treat with standard caution rather than immediate blocking given the legitimate business ownership
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk006-san139.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk006-san139.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 34% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 23% | 1 | 2 |
| geolocation | 40% | 2 | 3 |
| Overall | 24% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-23 06:22:08 UTC |
| Last Seen | 2026-06-28 20:34:11 UTC |
| Profile Built | 2026-06-29 02:36:17 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 24 |
Full dossier details are available via our API.