# IP Intelligence Briefing: 198.244.242.76
Classification: Moderate Risk | Status: Active | Date: 2026-06-20
---
## Executive Summary
IP address 198.244.242.76 is a cloud compute infrastructure endpoint operating from OVH's London data center (GB). The IP presents a moderate risk profile (risk score: 40) with no current threat indicators. The subnet exhibits high abuse density, warranting defensive monitoring and selective blocking.
---
## Technical Profile
| Attribute | Value |
|---|---|
| **IP Address** | 198.244.242.76/32 |
| **ASN** | 16276 (OVH SAS) |
| **Organization** | Ahrefs Pte Ltd Dmytro |
| **Location** | London, England, GB |
| **Infrastructure Type** | CloudCompute |
| **DNS Hostname** | proxy-uk007-san76.ahrefs.net |
| **Risk Score** | 40 (Moderate) |
| **Blacklist Count** | 0 |
| **Open Ports** | None detected |
---
## Network Context
Subnet Analysis (198.244.242.0/24):
- Abuse Density: 0.6406 (High abuse classification)
- Active Siblings: 206 of 256 IPs active
- Threat Siblings: 164 IPs flagged with threat indicators
- Risk Distribution: 57 medium-risk, 43 low-risk, 0 high-risk neighbors
The subnet demonstrates elevated abuse activity, though this specific IP (76) shows no active threat indicators.
---
## Observed Signals
Recent Activity: 21 observations tracked through June 2026. Key signals include:
- DNSSEC valid with CAA records present
- Single DNSBL listing (1 of 8 total lists checked)
- Subnet classified as high_abuse with inherited risk score of 25
- No known campaigns or correlated IPs detected
Network Classification:
- Cloud infrastructure: Yes (OVH hosting)
- CDN/Proxy/Vpn: No
- Mobile/Residential: No
---
## Threat Indicators
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Campaign Matches: None
- Behavioral Honeypot Hits: 0
---
## Recommended Actions
Defensive Mitigation:
- Firewall: Block at perimeter (iptables/nftables recommended)
- WAF: Configure Cloudflare/AWS WAF blocks for 198.244.242.76/32
- Monitoring: Track subnet activity given high abuse density
Justification:
While the IP presents no active threat indicators, the subnet's high abuse density (0.6406) and 164 threat siblings suggest potential for abuse. The IP's classification as cloud compute with no services open reduces immediate risk, but defensive blocking is recommended for environments with strict threat posture requirements.
---
Analyst Notes: IP 198.244.242.76 is part of a heavily utilized OVH cloud subnet with significant abuse activity. The individual IP shows no malicious behavior, but the neighborhood context warrants conservative blocking policies. Monitor for any behavioral changes or new threat indicators.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk007-san76.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk007-san76.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 25% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-18 21:27:59 UTC |
| Last Seen | 2026-06-28 07:55:09 UTC |
| Profile Built | 2026-06-29 01:59:49 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 26 |
Full dossier details are available via our API.