# IP Intelligence Briefing: 198.244.242.98
## Executive Summary
IP 198.244.242.98 is a cloud hosting address assigned to OVH infrastructure with a moderate risk score of 40. The IP resolves to ahosted domain (ahrefs.net) with no active services detected. While the IP itself shows no direct threat indicators, it operates within a high-abuse density subnet (0.6523) with 167 classified threat siblings across 256 total addresses in the /24 block.
## Ownership and Infrastructure
- Organization: Ahrefs Pte Ltd Dmytro (ASN 16276)
- Location: London, England, GB
- Provider: OVH (cloud hosting infrastructure)
- Network Block: 198.244.128.0/17
- DNS Record: proxy-uk007-san98.ahrefs.net
## Threat Assessment
The IP shows no direct threat indicators:
- Not a Tor exit node, VPN, proxy, or known attacker
- No active services detected (no open ports)
- No associated threat campaigns
- Zero blacklist entries, though listed on 1 of 8 DNSBLs
- Operator score: 0.2174 (Minimal classification)
## Neighborhood Risk Analysis
The IP resides in subnet 198.244.242.0/24 with concerning abuse metrics:
- Abuse Density: 0.6523 (high)
- Threat Siblings: 167 out of 256 total IPs
- Active Siblings: 219 IPs with recent activity
- Risk Distribution: 43 medium-risk, 57 low-risk neighbors
- Inherited Risk Score: 26 from subnet context
## Observation History
Recent intelligence collection (2026-06-20) confirms consistent infrastructure characteristics:
- Network classification: Cloud hosting with OVH provider
- Geolocation signals: London, GB with 750km accuracy radius
- Multiple signal types tracked with confidence levels between 0.28-0.85
## Recommended Security Actions
Based on risk profile and neighborhood context, the following controls are recommended:
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 198.244.242.98 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 198.244.242.98 drop` |
| nginx | `deny 198.244.242.98;` |
| pfSense | `198.244.242.98/32` |
| Cloudflare WAF | Block with expression: `ip.src eq 198.244.242.98` |
| AWS WAF | Add rule for `198.244.242.98/32` |
## Intelligence Context
This IP represents a legitimate cloud hosting address for Ahrefs infrastructure but operates in a high-risk neighborhood. The subnet's elevated abuse density suggests proximity to malicious activity, though this specific IP shows no direct threat indicators. SOC analysts should monitor the IP for behavioral changes while applying the recommended blocking rules as a precautionary measure against neighboring threat actors.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-uk007-san98.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk007-san98.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 22% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-20 05:44:22 UTC |
| Last Seen | 2026-06-28 11:09:47 UTC |
| Profile Built | 2026-06-29 06:09:07 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 25 |
Full dossier details are available via our API.