# IP Intelligence Briefing: 198.244.242.255/32
Classification: Moderate Risk (Score: 40)
Report Date: 2026-06-14
Prepared For: SOC Operations
## Executive Summary
The IP address 198.244.242.255 is a cloud-based infrastructure endpoint owned by Ahrefs Pte Ltd (Organization: Ahrefs Pte Ltd Dmytro, ASN: 16276, OVH) located in London, England. The address registers as a firewalled/cloud host with no active services and moderate reputation risk. No active threat indicators were observed, though the associated /24 subnet exhibits elevated abuse density.
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **IP Address** | 198.244.242.255/32 |
| **Risk Score** | 40 (Moderate Risk) |
| **Provider** | OVH |
| **Organization** | Ahrefs Pte Ltd Dmytro |
| **ASN** | 16276 |
| **Infrastructure Type** | CloudCompute |
| **Hosting** | Yes |
| **Location** | London, England, GB |
| **PTR Hostname** | proxy-uk007-san255.ahrefs.net |
| **Domain** | ahrefs.net |
## Threat Indicators
- Blacklist Status: 1 DNSBL listing (out of 8 total lists)
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Active Threats: None detected
- Campaign Matches: 0
- Known Campaigns: None
## Network Neighborhood Analysis
The /24 subnet (198.244.242.0/24) demonstrates elevated abuse characteristics:
- Abuse Density: 60.94% (high_abuse classification)
- Total Siblings: 256 IPs
- Active Siblings: 205 IPs
- Threat Siblings: 156 IPs
- Inherited Risk Score: 24
- Neighbor Risk Distribution: 100 medium-risk IPs, 0 high-risk, 0 low-risk
## Historical Observations
The IP has generated 23 historical observations with the following key findings:
- Subnet Classification: Consistently classified as high_abuse (abuse_density: 0.6094)
- Provider Consistency: OVH infrastructure
- Geolocation Confidence: 28% confidence for GB location
- Route Stability: Route changes detected (isRouteStable: false)
- Threat Persistence: 0 days of persistent malicious activity
- Ownership Changes: 0 ownership changes recorded
## Control Plane Analysis
- BGP Prefix: 198.244.128.0/17
- Origin ASN: 16276
- RPKI State: Not validated
- DNSSEC Valid: Yes
- Operator Score: 0.2174 (Minimal)
- DNSBL Listed Count: 1
## Security Recommendations
Based on the moderate risk profile and elevated neighborhood abuse density, the following actions are recommended:
1. Monitor Closely: The IP shows moderate risk with no active threats, but the high-abuse /24 subnet warrants continued monitoring
2. Traffic Analysis: Review inbound/outbound traffic patterns for anomalous behavior given the neighborhood context
3. Firewall Rules: Consider rate limiting for traffic from this /24 subnet given the 60.94% abuse density
4. Geolocation Validation: Verify the claimed London, GB location against actual traffic sources
## Risk Assessment
The IP presents a moderate risk profile typical of legitimate cloud hosting infrastructure used by Ahrefs. While no active threat indicators were detected, the elevated abuse density in the neighborhood suggests this subnet may be shared among multiple tenants with varying risk profiles. SOC analysts should monitor for behavioral anomalies rather than blocking the address outright.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk007-san255.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk007-san255.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 17% | 2 | 3 |
| ownership | 17% | 2 | 3 |
| reputation | 27% | 1 | 3 |
| geolocation | 31% | 2 | 3 |
| Overall | 22% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-11 21:44:06 UTC |
| Last Seen | 2026-06-27 20:24:25 UTC |
| Profile Built | 2026-06-28 14:30:28 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 28 |
Full dossier details are available via our API.