IP Intelligence Briefing: 198.244.242.218
Date: [Insert Date]
---
**Summary**
The IP 198.244.242.218 is associated with Ahrefs Pte Ltd (OVH ASN 16276) and classified as low risk (risk score: 25). It is geolocated in London, England and operates as a cloud compute service under OVH. No direct threat indicators (malware, C2, phishing) were detected.
---
**Key Findings**
1. Ownership & Infrastructure
- Owned by Ahrefs Pte Ltd (Dmytro), a legitimate cybersecurity firm.
- Hosted on OVH CloudCompute infrastructure (ASN 16276).
- Subnet 198.244.242.218/24 has moderate abuse density (45.31%), with 116 of 256 IPs flagged as high/medium risk.
2. Threat Observations
- No malicious activity detected in the last 30 days.
- No DNS-based threats, spam, or Tor exit nodes linked.
- BGP analysis shows stable routing with OVHβs 198.244.128.0/17 prefix.
3. Network Relationships
- Directly linked to proxy-uk007-san218.ahrefs.net (DNS hostname).
- Subnet neighbors include 118 active IPs, 116 of which are flagged as high/medium risk.
4. Behavioral Indicators
- No honeypot hits or anomalous traffic patterns.
- DNSSEC and CAA records are valid, with no DNSBL listings.
---
**Recommendations**
- Monitor Subnet Activity: The /24 subnet has a notable abuse density; prioritize monitoring neighbors for lateral movement or compromised hosts.
- Verify Cloud Configuration: Ensure OVH cloud instance is secured with WAF rules and access controls.
- Maintain Baseline: No immediate action required, but continue observing for changes in risk scores or DNS behavior.
Note: This IP appears benign, but its subnetβs mixed risk profile warrants ongoing scrutiny.
---
Source: IPDebrief Threat Intelligence Platform
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | proxy-uk007-san218.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk007-san218.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 21% | 1 | 2 |
| geolocation | 31% | 2 | 3 |
| Overall | 23% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-18 03:22:29 UTC |
| Last Seen | 2026-06-28 06:22:42 UTC |
| Profile Built | 2026-06-29 06:28:35 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 26 |
Full dossier details are available via our API.