# IP Intelligence Briefing: 198.244.240.211
Classification: Moderate Risk (40/100) | Status: Active | Date: 2026-06-20
## Executive Summary
IP address 198.244.240.211 is a cloud-hosted infrastructure endpoint operated by OVH (ASN 16276) within the Ahrefs Pte Ltd Dmytro organization. The IP resolves to proxy-uk006-san211.ahrefs.net and is located in London, England. While the endpoint shows no direct threat indicators, it operates within a high-abuse density subnet (0.8086) with 207 threat-adjacent siblings.
## Threat Profile
- Risk Score: 40 (Moderate)
- Infrastructure Type: CloudCompute/Hosting
- Network Role: Firewalled/No Services detected
- Blacklist Status: Listed on 1 of 8 threat feeds (high severity)
- Threat Indicators: No known campaigns, not Tor exit, not identified as spam source or known attacker
- DNSBL Listings: 1 active listing
## Network Context
The IP resides in subnet 198.244.240.0/24, classified as "high_abuse" with the following characteristics:
- Abuse Density: 0.8086 (elevated)
- Active Siblings: 168 of 256 addresses
- Threat Siblings: 207 (inherited risk: 32)
- Risk Distribution: 68 medium-risk, 32 low-risk neighbors
- Control Plane: BGP prefix 198.244.128.0/17, origin ASN 16276
## Historical Observations (22 events)
Recent signal activity indicates:
- 2026-06-20 04:36: Port scanning activity detected
- 2026-06-20 04:19: Provider classification as OVH hosting infrastructure
- 2026-06-20 04:11: Subnet abuse classification confirmed (high_abuse)
- 2026-06-20 04:10: Blacklist listings observed (max severity: high)
- Geolocation: Multi-signal inference places endpoint in GB region (55.38°N, -3.44°W) with 750km accuracy radius
## Relationship Graph
38 relationships detected, predominantly network-level associations (OVH_282347342). No certificate, hostname, or organizational linkages beyond network infrastructure.
## Recommended Actions
Due to moderate risk classification and high-abuse neighborhood context, the following blocking rules are recommended:
```
# iptables
iptables -A INPUT -s 198.244.240.211 -j DROP
# nftables
nft add rule inet filter input ip saddr 198.244.240.211 drop
# pfSense
198.244.240.211/32
# Cloudflare WAF
ip.src eq 198.244.240.211 โ action: block
# AWS WAF
Addresses: 198.244.240.211/32
Description: IPDebrief risk 40
```
## Analyst Notes
This IP operates legitimate hosting infrastructure (Ahrefs proxy endpoint) but within a subnet showing elevated abuse characteristics. The single DNSBL listing and recent port scanning activity warrant monitoring. Blocking is recommended for defensive posture, particularly for high-value internal targets. Consider implementing rate limiting or connection throttling as an alternative to outright blocking to minimize operational impact on legitimate Ahrefs traffic while mitigating abuse risk from adjacent subnet addresses.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk006-san211.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk006-san211.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 26% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-18 03:22:29 UTC |
| Last Seen | 2026-06-28 06:18:17 UTC |
| Profile Built | 2026-06-29 00:22:16 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 28 |
Full dossier details are available via our API.