# IP Intelligence Briefing: 198.244.242.107/32
Classification: MODERATE RISK INFRASTRUCTURE IP
Report Date: 2026-06-15
Data Source: IPDebrief Intelligence Platform
## Executive Summary
IP 198.244.242.107 is a cloud computing infrastructure endpoint hosted on OVH's UK datacenter infrastructure. The IP resolves to ahrefs.net domain and operates under Ahrefs Pte Ltd Dmytro organization. Risk assessment indicates Moderate Risk (Score: 40) with no direct threat indicators, though the subnet demonstrates elevated abuse characteristics.
## Key Findings
Infrastructure Profile
- Organization: Ahrefs Pte Ltd Dmytro
- ASN: 16276 (OVH)
- Location: London, England, GB (750km accuracy radius)
- Network Classification: CloudCompute / Hosting
- DNS Resolution: proxy-uk007-san107.ahrefs.net
- Service Status: Firewalled / No Services Detected
Risk Assessment
- Overall Risk Score: 40/100 (Moderate Risk)
- Operator Score: 0.2174 (Minimal operator risk)
- DNSBL Listings: 1 out of 8 total blacklists
- Known Attackers: No
- Tor Exit Node: No
- Spam Source: No
Neighborhood Analysis
- Subnet: 198.244.242.107/24
- Abuse Density: 0.6289 (High Abuse Classification)
- Active Siblings: 206 of 256 total IPs
- Threat Siblings: 161 identified as threats
- Inherited Risk: 25 from subnet context
Historical Observations
- Total Signals: 17 observations
- Most Recent: 2026-06-15 04:17 UTC
- Geolocation Confidence: 0.28 (GB inferred)
- DNS Resolution Confidence: 0.80 (ahrefs.net)
- Threat Persistence: No persistent malicious activity detected
Network Relationships
- Network Association: Multiple relationships to OVH_282347343
- DNS Associations: 18+ associations to proxy-uk007-san107.ahrefs.net
## SOC Recommendations
Monitoring Priority
MEDIUM โ Monitor for abuse patterns within the /24 subnet context
Recommended Actions
- Allow if traffic is confirmed legitimate Ahrefs service
- Block if originating from unexpected sources or showing port scanning behavior
- Investigate any connections from this subnet showing anomalous traffic patterns
Key Indicators
- Block List: Listed on 1 DNSBL (verify current status)
- Certificate Status: No TLS certificates observed
- Open Ports: None detected
- BGP Prefix: 198.244.128.0/17 (stable routing)
Contextual Notes
The IP belongs to a high-abuse density subnet (0.6289) with 161 threat-identified siblings. While this specific endpoint shows no direct threat indicators, SOC teams should correlate traffic with known Ahrefs services and monitor for lateral movement within the subnet. The infrastructure appears to be a legitimate cloud-hosted proxy endpoint for ahrefs.net services.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk007-san107.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk007-san107.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 25% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-18 03:22:29 UTC |
| Last Seen | 2026-06-28 06:21:01 UTC |
| Profile Built | 2026-06-29 00:26:55 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 26 |
Full dossier details are available via our API.