# Intelligence Briefing: 198.244.242.192
## Executive Summary
IP address 198.244.242.192 is a moderate-risk (50/100) cloud infrastructure endpoint operated by OVH in London, England. While the IP itself shows no direct malicious activity, it resides within a high-abuse subnet (198.244.242.0/24) with 167 active threat siblings out of 219 monitored IPs. The address is associated with the ahrefs.net domain and presents a "Firewalled / No Services" profile with no open ports detected.
## Infrastructure Profile
- Organization: Ahrefs Pte Ltd Dmytro (ASN: 16276)
- Infrastructure: CloudCompute hosting environment
- Geolocation: London, England, GB (confidence: 750km radius)
- Network Classification: Cloud hosting provider infrastructure
- DNS Resolution: proxy-uk007-san192.ahrefs.net (ahrefs.net)
- Open Ports: None detected
- TLS/HTTP Services: None active
## Threat Assessment
- Overall Risk Score: 50 (Moderate)
- Abuse Confidence: No specific threat indicators
- Blacklist Status: Clean (0 direct blacklists)
- DNSBL Listed: 2 of 8 total lists
- Threat Feeds: No known campaigns or attacker attribution
- Tor/VPN/Proxy: Negative
- Known Attacker: No
## Neighborhood Analysis
The IP belongs to subnet 198.244.242.0/24, which demonstrates concerning abuse characteristics:
- Abuse Density: 0.6523 (High)
- Subnet Classification: high_abuse
- Inherited Risk Score: 26
- Active Siblings: 219 of 256 total
- Threat Siblings: 167 active malicious IPs in the /24
- Risk Distribution: 56 low-risk, 44 medium-risk, 0 high-risk neighbors
## Observational History
Analysis of 21 signal observations reveals:
- Provider Consistency: OVH infrastructure identified across all observations
- Infrastructure Type: CloudCompute classification maintained throughout
- Geographic Consistency: GB location with 0.28 confidence
- Abuse Density: Persistently high at 0.6523 across observations
- Operator Score: 0.2174 (Minimal operator risk)
## Network Relationships
- Total Relationships: 38
- Primary Association: Same Network (OVH_282347343) - all relationships map to the same network block
- No Cross-Organization Links: No relationships with other organizations or domains detected
## Recommended Actions
Based on the risk profile and neighborhood context:
1. Monitor Closely: Given the high-abuse subnet density, monitor for traffic anomalies
2. Traffic Analysis: No services are open, but investigate any outbound connections
3. Contextual Awareness: The subnet contains 167 confirmed threat IPs; treat with elevated scrutiny
4. DNS Monitoring: Watch for changes in hostname resolution patterns
5. Firewall Rules: No immediate blocking recommended, but log all traffic
## Intelligence Conclusion
This IP represents a legitimate cloud hosting endpoint within a high-abuse subnet. While the specific address shows no malicious activity, the neighborhood context warrants ongoing monitoring. The association with ahrefs.net suggests potential crawler/proxy functionality rather than malicious use. Security teams should monitor for any behavioral changes that might indicate compromised infrastructure within the broader subnet.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk007-san192.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk007-san192.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 23% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-20 05:44:21 UTC |
| Last Seen | 2026-06-28 11:08:10 UTC |
| Profile Built | 2026-06-29 05:14:20 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 24 |
Full dossier details are available via our API.