# IP Intelligence Briefing: 198.244.242.175/32
## Executive Summary
IP address 198.244.242.175 presents a moderate risk profile (score: 40) associated with cloud infrastructure hosted by OVH in London, England. The IP operates under the ahrefs.net domain but demonstrates concerning neighborhood-level abuse patterns with a high-abuse subnet classification (198.244.242.0/24).
## Risk Assessment
Overall Risk Score: 40 (Moderate Risk)
Infrastructure Type: Cloud Compute / Hosting
Provider: OVH (ASN 16276)
Registration: Ahrefs Pte Ltd Dmytro
Key Risk Indicators
- DNSBL listed: 1 of 8 total blacklist checks (high severity)
- Operator score: 0.2174 (labeled "Minimal")
- Subnet abuse density: 0.6641 (classified as high_abuse)
- Inherited risk from neighborhood: 26
## Geographic and Network Context
Location: London, England, GB
Timezone: Europe/London
BGP Prefix: 198.244.128.0/17
Route Stability: False (0 route changes in 30 days)
DNSSEC: Valid
## Infrastructure Analysis
- Infrastructure Classification: Cloud Compute, Hosting
- Connection Type: Firewalled / No Services
- DNS Resolution: proxy-uk007-san175.ahrefs.net (ahrefs.net)
- Open Ports: None detected
- TLS Certificate: Not observed
- HTTP Services: Not active
## Neighborhood Intelligence (198.244.242.0/24)
- Total Siblings: 256
- Active Siblings: 227
- Threat Siblings: 170
- Risk Distribution: High (0), Medium (22), Low (78)
- Classification: High abuse subnet
The subnet exhibits elevated malicious activity with 170 threat siblings out of 227 active IPs. Multiple neighboring addresses show risk scores between 25-50, indicating systemic abuse patterns within the /24 block.
## Historical Observations (22 Total Signals)
Recent signal history reveals:
- June 2026: Cloud infrastructure detection (OVH)
- June 2020: High-abuse subnet classification signals
- DNSBL Activity: 1 listing recorded with high severity
- Threat Persistence: 0 days (not persistently malicious)
- Ownership Changes: 0 (stable ownership)
## Relationship Graph
37 relationships detected, primarily network-level associations with OVH infrastructure (OVH_282347343). No certificate, organization, or hostname relationships beyond the network level were identified.
## Threat Indicators
- Campaign Correlation: None
- Known Attacker: False
- Tor Exit Node: False
- Proxy/VPN: False
- Spam Source: False
- Threat Feeds: None matched
## Recommended Security Actions
Firewall Rules
iptables:
```
iptables -A INPUT -s 198.244.242.175 -j DROP
```
nftables:
```
nft add rule inet filter input ip saddr 198.244.242.175 drop
```
nginx:
```
deny 198.244.242.175;
```
Cloud/WAF Recommendations
- Cloudflare WAF: Block IP with expression `ip.src eq 198.244.242.175`
- AWS WAF: Add 198.244.242.175/32 to blocked address set
- pfSense: 198.244.242.175/32
## Analyst Notes
While the individual IP (198.244.242.175) shows no direct threat indicators or active malicious services, the high-abuse subnet classification (170 threat siblings) warrants defensive blocking. The moderate risk score of 40 combined with DNSBL presence and neighborhood abuse patterns suggests potential for compromised or misconfigured infrastructure in the same /24 block. Consider implementing subnet-level controls for 198.244.242.0/24 where operational requirements permit.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk007-san175.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk007-san175.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-22 09:12:37 UTC |
| Last Seen | 2026-06-28 18:36:56 UTC |
| Profile Built | 2026-06-29 06:40:15 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 25 |
Full dossier details are available via our API.