# IP Intelligence Briefing: 198.244.240.220/32
## Executive Summary
IP 198.244.240.220 presents a moderate risk profile with a risk score of 40. The address belongs to OVH's cloud infrastructure in London, England, and is associated with Ahrefs Pte Ltd Dmytro. While the IP itself shows no active threat indicators, the /24 subnet exhibits high abuse density (83.6%), warranting defensive measures.
## Ownership and Geolocation
- ASN: 16276
- Organization: Ahrefs Pte Ltd Dmytro
- Network: OVH cloud compute infrastructure
- Location: London, England, GB
- Registration: ARIN RIR
## Network Classification
- Infrastructure Type: Cloud compute (OVH)
- Hosting: Yes
- CDN/VPN/Proxy: No
- Tor Exit: No
- Mobile/Residential: No
- Bogon: No
- Anycast: No
## DNS Analysis
- PTR Hostname: proxy-uk006-san220.ahrefs.net
- Domain: ahrefs.net
- Forward Resolution: 1 hostname confirmed
- Email Authentication: No SPF, DMARC, or TXT records configured
## Security Posture
- Open Ports: None detected
- HTTP Services: None detected
- TLS Certificate: None
- DNSBL Status: Listed on 1 of 8 threat feeds
- Reputation: Moderate risk (score 40/100)
## Neighborhood Assessment
The /24 subnet 198.244.240.220/24 demonstrates significant abuse activity:
- Abuse Density: 0.8359 (high abuse)
- Total Siblings: 256
- Active Siblings: 199
- Threat Siblings: 214 (83.6%)
- Risk Distribution: 47 medium-risk, 53 low-risk IPs in subnet
## Historical Signals
22 observations recorded with consistent cloud infrastructure classification. Abuse density signals observed across multiple observation windows, indicating persistent subnet-level activity patterns.
## Related Entities
37 relationships identified, primarily network-level associations with OVH_282347342.
## Recommended Actions
Based on the IP's risk profile and subnet context, the following defensive measures are recommended:
Firewall Rules:
- iptables: `iptables -A INPUT -s 198.244.240.220 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 198.244.240.220 drop`
- nginx: `deny 198.244.240.220;`
- pfSense: `198.244.240.220/32`
WAF Configuration:
- Cloudflare WAF: Block with expression `ip.src eq 198.244.240.220`
- AWS WAF: Add `198.244.240.220/32` to allow list or block rule
## Intelligence Assessment
The IP should be treated as a defensive priority due to subnet-level abuse activity, despite the individual address showing no active malicious indicators. The high concentration of threat-sibling IPs within the /24 suggests coordinated abuse infrastructure. Consider blocking the entire /24 subnet or implementing rate limiting if business requirements permit legitimate traffic from this range.
---
*Analysis generated from IPDebrief intelligence platform data.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk006-san220.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk006-san220.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 32% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 20% | 2 | 3 |
| reputation | 27% | 1 | 3 |
| geolocation | 31% | 2 | 3 |
| Overall | 22% | 9 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-20 05:44:21 UTC |
| Last Seen | 2026-06-28 11:04:59 UTC |
| Profile Built | 2026-06-29 11:10:07 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 26 |
Full dossier details are available via our API.