# IP INTELLIGENCE BRIEFING: 198.244.242.74/32
Classification: Low Risk โ Cloud Infrastructure
Date: June 25, 2026
Analyst: IPDebrief Intelligence Team
---
## EXECUTIVE SUMMARY
Target IP 198.244.242.74 is a low-risk cloud compute endpoint operated by Ahrefs Pte Ltd (OVH network). The address resolves to legitimate ahrefs.net infrastructure with no threat indicators, blacklisting, or malicious activity observed. Recommended action: MONITOR ONLY.
---
## RISK ASSESSMENT
| Metric | Value |
|---|---|
| Overall Risk Score | 25/100 (Low Risk) |
| Abuse Confidence Score | Not Calculated |
| Blacklist Count | 0 |
| Threat Indicators | None |
| Known Campaigns | None |
Risk Breakdown: Provider score: 0, Authority score: 0. No stability data available. Risk derived from minimal operator score (0.1/1.0) and mixed subnet classification.
---
## OWNERSHIP & INFRASTRUCTURE
- Organization: Ahrefs Pte Ltd Dmytro
- ASN: 16276 (OVH)
- Network Role: Cloud Compute / Hosting
- Infrastructure Type: CloudCompute
- Geolocation: London, England, GB (Europe/London timezone)
- Geolocation Confidence: 750km radius (consensus from multiple sources)
BGP Context:
- Origin ASN: 16276
- BGP Prefix: 198.244.128.0/17
- Route Stability: Unstable (isRouteStable: false)
- RPKI State: Not Evaluated
---
## DNS & NETWORK SERVICES
DNS Resolution:
- PTR Hostname: proxy-uk007-san74.ahrefs.net
- Forward Resolution: proxy-uk007-san74.ahrefs.net
- Domain: ahrefs.net
- Forward Confirmation: Incomplete
Services:
- Open Ports: None detected
- TLS Certificate: None
- HTTP Title: None
- Connection State: Firewalled / No Services
Security Headers:
- HSTS: Not Present
- CSP: Not Present
- HTTP/2: Not Detected
---
## THREAT INTELLIGENCE
Threat Profile:
- Is Tor Exit Node: No
- Is Known Attacker: No
- Is Spam Source: No
- Is VPN/Proxy: No
- Is Mobile/Residential: No
Campaign Correlation:
- Campaign Likelihood: None
- CERT Matches: 0
- Correlated IPs: 0
Behavioral Indicators:
- Honeypot Hits: 0
- Threat Persistence: 0 days
- Persistently Malicious: No
---
## NEIGHBORHOOD ANALYSIS
Subnet Context: 198.244.242.0/24
- Classification: Mixed
- Abuse Density: 0.3242 (Moderate)
- Total Siblings: 256
- Active Siblings: 229
- Threat Siblings: 83
Risk Distribution in Subnet:
- High Risk: 0 IPs
- Medium Risk: 76 IPs
- Low Risk: 24 IPs
Sample Neighbor Risk Scores:
- 198.244.242.0: 50 (High)
- 198.244.242.1: 40 (Medium)
- 198.244.242.3: 50 (High)
---
## OBSERVATION HISTORY
Total Observations: 24 signals recorded
Latest Observation: June 25, 2026
Recent Signal Types:
- DNS Resolution to ahrefs.net (confidence: 0.80)
- Geolocation inference: GB, London (confidence: 0.28)
- Network classification: CloudCompute, OVH (confidence: 0.90)
- Subnet abuse density: 0.3242 (confidence: 0.75)
- Operator score: 0.1 (confidence: 0.60)
Temporal Analysis:
- Ownership Changes: 0
- Threat Observation Count: 1
- Is Persistently Malicious: No
---
## RELATIONSHIP GRAPH
Total Relationships: 75
Primary Link Type: Same Network (OVH_282347343)
- 70+ relationships to same network segment
- No organizational or hostname relationships beyond network classification
---
## RECOMMENDED ACTIONS
Security Recommendations: None Required
Rationale: Target IP shows no malicious indicators. Low risk score, legitimate cloud hosting infrastructure, and no threat intelligence correlation.
If Blocking is Required: No firewall rules generated due to benign risk profile.
---
## INTELLIGENCE NARRATIVE
IP 198.244.242.74 operates as part of OVH's cloud infrastructure network (ASN 16276) under Ahrefs Pte Ltd ownership. The endpoint resolves to ahrefs.net with proxy hostname proxy-uk007-san74.ahrefs.net, consistent with legitimate SEO analytics infrastructure. No malicious activity, blacklisting, or threat indicators have been observed.
The subnet 198.244.242.0/24 exhibits mixed classification with moderate abuse density (0.3242). Of 256 total siblings, 229 are active and 83 are classified as threats. However, the target IP itself maintains a low risk score of 25/100 with no direct threat associations.
Geolocation validation confirms UK-based origin with 94-95ms average RTT from probe locations. No Tor, VPN, or proxy characteristics detected. The endpoint is firewalled with no open services detected.
Recommendation: Treat as benign cloud infrastructure. No blocking or mitigation required. Continue standard monitoring as part of general network hygiene.
---
*Generated by IPDebrief Intelligence Platform. Data timestamp: June 25, 2026.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk007-san74.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk007-san74.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 17% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 27% | 1 | 3 |
| geolocation | 37% | 2 | 3 |
| Overall | 22% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-10 04:11:45 UTC |
| Last Seen | 2026-06-27 17:01:46 UTC |
| Profile Built | 2026-06-28 11:08:28 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 28 |
Full dossier details are available via our API.