# IP INTELLIGENCE BRIEFING
Target: 198.244.240.45/32
Classification: Moderate Risk (Score: 40/100)
Date: Intelligence generated from full profile analysis
---
## EXECUTIVE SUMMARY
IP 198.244.240.45 operates as cloud-hosted infrastructure under OVH (ASN 16276) within the Ahrefs Pte Ltd ecosystem. While the IP resolves to legitimate Ahrefs domains (proxy-uk006-san45.ahrefs.net), it is situated in a high-abuse-density subnet (198.244.240.0/24) with 83% abuse density. The IP presents as firewalled with no active services but is listed on 8 DNSBLs with one high-severity listing.
---
## INFRASTRUCTURE PROFILE
| Attribute | Value |
|---|---|
| **Risk Score** | 40 (Moderate Risk) |
| **ASN/Org** | 16276 / Ahrefs Pte Ltd Dmytro |
| **Location** | London, England, GB (750km accuracy) |
| **Infrastructure** | Cloud Compute (OVH hosting) |
| **DNS** | proxy-uk006-san45.ahrefs.net |
| **Open Ports** | None detected |
| **Network Role** | Firewalled / No Services |
---
## THREAT INDICATORS
- Blacklist Status: Listed on 8 DNSBLs (1 high-severity)
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Known Campaigns: None identified
- Abuse Confidence: Moderate
---
## NEIGHBORHOOD ANALYSIS
Subnet: 198.244.240.0/24
- Abuse Density: 0.8359 (High Abuse Classification)
- Total Siblings: 256
- Active Siblings: 199 (78% utilization)
- Threat Siblings: 214 (85% of active)
- Risk Distribution: 47 medium, 53 low, 0 high
The subnet exhibits concentrated abuse activity despite hosting Ahrefs infrastructure, suggesting potential infrastructure sharing or compromised co-located assets.
---
## OBSERVATION HISTORY
Total Observations: 19
- Recent Activity: June 20, 2026 (5 observations)
- DNSBL Listings: Confirmed 8 total lists with high-severity categorization
- Subnet Classification: Persistent high_abuse designation
- Provider Consistency: OVH (cloud hosting)
- Operator Score: 0.2174 (Minimal operator risk)
---
## CONTROL PLANE DATA
- BGP Prefix: 198.244.128.0/17
- Route Stability: False
- RPKI State: Null
- Route Changes (30d): 0
- DNSSEC: Valid
- CAA Records: Present
---
## RELATIONSHIP MAPPING
- Total Relationships: 37
- Primary Association: Same Network (OVH_282347342)
- Network-Level Links: 32+ redundant network associations
- No direct links to: Hostnames, organizations, or certificates outside network infrastructure
---
## RECOMMENDED ACTIONS
1. Monitor subnet abuse patterns โ High abuse density (0.8359) warrants continued surveillance of 198.244.240.0/24 range
2. Verify Ahrefs association โ Confirm legitimate business use despite infrastructure sharing with high-risk peers
3. DNSBL monitoring โ Track changes in blacklist status across all 8 listed feeds
4. Geolocation validation โ London location aligns with expected Ahrefs operations but monitor for anomalies
5. No immediate blocking required โ Moderate risk score with no active threat indicators; observe rather than block
---
Analyst Notes: The IP presents a legitimate business entity (Ahrefs) operating within a high-risk hosting environment. Recommend maintaining monitoring stance rather than defensive blocking, but treat inbound connections from this subnet with elevated scrutiny.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk006-san45.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk006-san45.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 22% | 9 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-20 05:44:21 UTC |
| Last Seen | 2026-06-28 11:06:25 UTC |
| Profile Built | 2026-06-29 05:12:01 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 22 |
Full dossier details are available via our API.