# IP Intelligence Briefing: 198.244.240.65/32
## Executive Summary
IP address 198.244.240.65 is a moderate-risk (40) address operated by Ahrefs Pte Ltd Dmytro (ASN 16276) within OVH infrastructure. The IP resolves to proxy-uk006-san65.ahrefs.net and is geolocated to London, England. While no direct threat indicators were observed, the subnet exhibits high abuse density (0.7695), classifying the environment as high-abuse with 197 threat siblings detected across 256 total IPs.
## Technical Profile
| Attribute | Value |
|---|---|
| Risk Score | 40 (Moderate Risk) |
| ASN | 16276 (OVH) |
| Organization | Ahrefs Pte Ltd Dmytro |
| Location | London, England (GB) |
| Network Role | Hosting Provider |
| DNS Record | proxy-uk006-san65.ahrefs.net |
| Open Ports | None detected (Firewalled) |
| DNSBL Listed | 1 of 8 total lists |
## Neighborhood Assessment
The /24 subnet 198.244.240.65/24 demonstrates elevated abuse characteristics:
- Abuse Density: 0.7695 (High Abuse classification)
- Threat Siblings: 197 out of 256 IPs
- Active Siblings: 163
- Inherited Risk Score: 30
- Risk Distribution: 100 medium-risk neighbors, 0 high-risk neighbors
## Threat Indicators
- No known campaigns or threat feed matches
- Not identified as Tor exit node, known attacker, or spam source
- Blacklist count: 0
- No active threat indicators in current profile
## Historical Observations
Analysis of 21 signal observations indicates:
- Consistent subnet abuse density patterns
- Persistent association with OVH infrastructure (AS16276)
- DNS resolution to ahrefs.net domain
- Operator score: 0.2174 (Minimal operator risk)
- No persistent malicious behavior detected
## Recommended Actions
Based on the moderate risk profile and high-abuse neighborhood context, consider the following mitigations:
Firewall Rules:
- iptables: `iptables -A INPUT -s 198.244.240.65 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 198.244.240.65 drop`
- Cloudflare WAF: Block with expression `ip.src eq 198.244.240.65`
- AWS WAF: Add to block list `198.244.240.65/32`
Contextual Decision Factors:
- The IP resolves to Ahrefs infrastructure, a legitimate SEO analytics company
- No open services detected (firewalled configuration)
- Moderate risk score (40) below typical malware distribution thresholds
- Recommendation to block is probabilistic; correlate with additional threat signals before enforcement
## Intelligence Assessment
This IP represents infrastructure associated with Ahrefs operating on OVH hosting. While the address itself shows no direct malicious indicators, the high-abuse neighborhood context warrants monitoring. SOC teams should evaluate whether traffic patterns align with expected Ahrefs service usage or exhibit anomalous behavior.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk006-san65.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk006-san65.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 27% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-18 03:22:29 UTC |
| Last Seen | 2026-06-28 06:19:10 UTC |
| Profile Built | 2026-06-29 00:24:37 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 27 |
Full dossier details are available via our API.