IP Intelligence Briefing: 198.244.242.252/32
*Generated via IPDebrief Analysis*
---
**1. Core Profile**
- Risk Score: Moderate (40/100) | Provider: OVH | Organization: Ahrefs Pte Ltd (SEO services)
- Geolocation: London, England, UK (geo-plausibility flagged as uncertain).
- Network Role: CloudCompute infrastructure (OVH-hosted, no open services detected).
- Threat Indicators: No direct malicious activity observed; no spam, phishing, or known attacker associations.
---
**2. Subnet Analysis**
- Subnet: 198.244.242.0/24 | Abuse Density: 59.77% (high-risk classification).
- Neighbor Risk: 100 IPs in subnet, with 97 moderate-risk and 3 low-risk neighbors.
- Key Sibling IPs:
- 198.244.242.0 (risk score 40)
- 198.244.242.1 (risk score 40)
- 198.244.242.2 (risk score 40)
- *Note*: Subnet contains 153 threat-associated IPs, suggesting potential for lateral movement or shared infrastructure risks.
---
**3. DNS & Hosting**
- PTR Hostname: `proxy-uk007-san252.ahrefs.net` (linked to Ahrefsβ proxy network).
- Domain: `ahrefs.net` (no email authentication records detected).
- Cloud Context: Likely part of Ahrefsβ distributed scraping or proxy infrastructure.
---
**4. Temporal & Behavioral Signals**
- Observation History:
- Last 30 days show stable risk profile (no spikes in threat indicators).
- DNS and network attributes remain consistent.
- Behavioral Flags: No honeypot or botnet activity detected.
---
**5. Security Recommendations**
- Monitoring: Track subnet for unusual traffic patterns due to high abuse density.
- Firewall: Consider blocking or monitoring traffic to/from this subnet if it conflicts with internal policies.
- Validation: Verify geolocation accuracy, as coordinates are uncertain.
- Context: Ahrefs is a legitimate company, but its infrastructure may be exploited by third parties.
---
Conclusion: This IP is part of a high-risk subnet but shows no direct malicious activity. Monitor its environment and correlate with Ahrefsβ broader infrastructure for potential indirect threats.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | proxy-uk007-san252.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk007-san252.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 22% | 9 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-21 21:00:00 UTC |
| Last Seen | 2026-06-28 15:51:18 UTC |
| Profile Built | 2026-06-29 03:56:09 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 22 |
Full dossier details are available via our API.