# IPDEBRIEF INTELLIGENCE BRIEFING
Target: 198.244.242.155/32
Date: Current
Classification: MODERATE RISK
## EXECUTIVE SUMMARY
IP 198.244.242.155 operates as firewalled cloud compute infrastructure within the OVH network (ASN 16276) in London, GB. The IP resolves to Ahrefs proxy hostname and presents a moderate risk score of 40. While the specific address shows no direct threat indicators, its /24 subnet exhibits elevated abuse density (0.6641) with 170 threat siblings among 207 active neighbors.
## OWNERSHIP & GEOLOCATION
- ASN: 16276 (OVH)
- Organization: Ahrefs Pte Ltd Dmytro
- Location: London, England, GB
- Infrastructure Type: Cloud Compute, Hosting
- Network Role: Cloud infrastructure with firewalled/no services detected
## THREAT INDICATORS
- Risk Score: 40 (Moderate Risk)
- Threat Indicators: None detected on this IP
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0
- Campaign Likelihood: None
## NETWORK BEHAVIOR
- Open Ports: None detected
- DNS Resolution: proxy-uk007-san155.ahrefs.net
- Infrastructure: Cloud-hosted (OVH), firewalled
- Control Plane: Route stable, DNSSEC valid, CAA records present
## SUBNET CONTEXT (198.244.242.0/24)
- Abuse Density: 0.6641 (HIGH ABUSE CLASSIFICATION)
- Total Siblings: 256
- Active Siblings: 207
- Threat Siblings: 170
- Inherited Risk: 26
- Risk Distribution: All 100 sampled neighbors show medium risk (40-50)
## OBSERVATION HISTORY
- Total Observations: 25
- Threat Persistence Days: 0
- Recent Activity: Signals observed June 2026 with minimal operator scores (0.2174)
- Status: Not persistently malicious
## RECOMMENDATIONS
1. Monitor Subnet Context: While this IP shows no direct threats, the subnet's high abuse density warrants continued monitoring.
2. DNS Reputation: The Ahrefs proxy hostname suggests legitimate use, but correlate with traffic patterns.
3. No Immediate Action Required: IP is firewalled with no open services and no direct threat indicators.
4. Correlation Analysis: Monitor for connection attempts to this subnet given the 170 threat-sibling count.
## INDICATORS OF COMPROMISE (IOC)
- IP: 198.244.242.155
- Hostname: proxy-uk007-san155.ahrefs.net
- ASN: 16276
- Network: 198.244.242.0/24
Analyst Note: This IP represents legitimate cloud hosting infrastructure with a clean direct profile. However, SOC analysts should maintain awareness of the subnet's elevated abuse context when evaluating traffic patterns or connection requests to this network segment.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk007-san155.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk007-san155.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 38% | 2 | 5 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 27% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 23% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:06 UTC |
| Last Seen | 2026-06-27 02:53:23 UTC |
| Profile Built | 2026-06-28 03:00:07 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 31 |
Full dossier details are available via our API.