# IP Intelligence Briefing: 198.244.242.202
## Executive Summary
IP 198.244.242.202 is assigned to Ahrefs Pte Ltd Dmytro (ASN 16276) and hosted on OVH cloud infrastructure in London, England. While currently classified as Moderate Risk (risk score: 50), the IP resides within a high-abuse subnet (198.244.242.0/24) with an abuse density of 0.6719, indicating elevated neighborhood-level risk.
## Ownership and Infrastructure
- Organization: Ahrefs Pte Ltd Dmytro
- ASN: 16276 (OVH)
- Location: London, England, GB
- Infrastructure Type: Cloud compute (OVH hosting environment)
- DNS Resolution: proxy-uk007-san202.ahrefs.net (ahrefs.net domain)
## Risk Assessment
- Overall Risk Score: 50/100 (Moderate)
- Provider Score: 0
- Authority Score: 0
- Stability: No persistent ownership or threat persistence observed
- Threat Indicators: No active threat indicators; not identified as Tor exit, known attacker, or spam source
- DNSBL Listings: Listed on 2 of 8 total DNSBLs
## Neighborhood Analysis
The IP operates within the 198.244.242.0/24 subnet, characterized as high abuse:
- Abuse Density: 0.6719 (67.19%)
- Total Siblings: 256
- Active Siblings: 206
- Threat Siblings: 172
- Risk Distribution: 100 medium-risk neighbors, 0 high-risk, 0 low-risk
## Historical Observations
Analysis of 23 signal observations reveals:
- Recent DNSBL listings observed as of June 17, 2026
- Consistent DNS resolution to ahrefs.net infrastructure
- No evidence of persistent malicious activity or campaign correlation
- Operator score: 0.2174 (labeled "Minimal")
## Technical Configuration
- Open Ports: None detected (Firewalled/No Services)
- TLS Certificate: None
- HTTP Services: None active
- DNSSEC: Valid
- CAA Records: Present
## Recommended Actions
Based on the moderate risk profile and neighborhood abuse context, defensive measures include:
Firewall Rules:
- iptables: `iptables -A INPUT -s 198.244.242.202 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 198.244.242.202 drop`
- nginx: `deny 198.244.242.202;`
- pfSense: Block 198.244.242.202/32
WAF Configuration:
- Cloudflare WAF: Block IP with expression `ip.src eq 198.244.242.202`
- AWS WAF: Add IP 198.244.242.202/32 to IP set
## Analyst Notes
While the IP is registered to legitimate Ahrefs infrastructure, the high-abuse neighborhood context suggests potential for compromise or abuse. The lack of active services and firewalling indicates the IP may be dormant or used for specific purposes. Monitoring is recommended due to the subnet-level abuse profile, but immediate blocking may be warranted depending on organizational threat tolerance.
---
*Report generated: IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk007-san202.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk007-san202.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 33% | 2 | 3 |
| Overall | 25% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-22 09:12:38 UTC |
| Last Seen | 2026-06-28 18:37:07 UTC |
| Profile Built | 2026-06-29 06:40:15 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 25 |
Full dossier details are available via our API.