IP Intelligence Briefing: 198.244.240.217
*Generated via IPDebrief tools*
---
1. Core Profile
- Risk Score: 50 (Moderate Risk)
- Ownership: Ahrefs Pte Ltd (ASN 16276, OVH provider)
- Geolocation: London, England, GB (high plausibility)
- Network Role: Hosting infrastructure (OVH, no public services)
- Threat Indicators: No malicious activity detected
2. Observation History
- Last 30 days: 24 signals recorded (DNS, geolocation, abuse lists).
- Notable:
- DNS association with `proxy-uk006-san217.ahrefs.net` (likely legitimate).
- Subnet abuse density: 51.17% (high-risk classification).
- No persistent malicious behavior or campaign ties.
3. Relationships
- Network: Linked to OVH subnet `198.244.128.0/17` (high abuse classification).
- DNS: Resolves to `proxy-uk006-san217.ahrefs.net` (Ahrefs infrastructure).
- No known connections to C2 servers, malware, or botnets.
4. Subnet Analysis
- /24 subnet: 256 IPs, 101 active, 131 flagged as threats.
- Risk Distribution: 80% medium-risk neighbors, 20% low-risk.
- Abuse Density: 51.17% (high-risk subnet).
5. Recommendations
- Monitor for unexpected traffic patterns, given the subnetβs high abuse density.
- Verify DNS resolution ties to Ahrefsβ legitimate infrastructure.
- Consider restricting access to this subnet if it hosts sensitive services.
- No immediate mitigation required for the IP itself, but contextualize within the subnetβs risk profile.
---
Conclusion: This IP is part of a high-risk subnet associated with a legitimate hosting provider. While no direct malicious activity is observed, the environment warrants closer monitoring for potential lateral movement or abuse.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | proxy-uk006-san217.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk006-san217.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-19 21:39:51 UTC |
| Last Seen | 2026-06-28 09:53:14 UTC |
| Profile Built | 2026-06-29 03:58:29 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 25 |
Full dossier details are available via our API.