# IP Intelligence Briefing: 202.8.41.63/32
Date Generated: 2026-06-26
IP Classification: Crawler/Infrastructure Host (Ahrefs)
Risk Level: LOW (25/100)
---
## Executive Summary
IP 202.8.41.63 is a low-risk infrastructure host belonging to Ahrefs Pte Ltd's crawler network (AHREFS-CRAWLER-A-USA). The address operates as a single-service SSH host with minimal threat indicators. While geographic validation shows inconsistencies, the IP demonstrates persistent benign behavior across 19 observation periods with no active malicious campaigns or significant reputation degradation.
---
## Technical Profile
Ownership & Network:
- ASN: 140577 (Ahrefs Pte Ltd administrator)
- Netname: AHREFS-CRAWLER-A-USA
- CIDR Block: 202.8.40.0/23
- RIR: APNIC
- Service Purpose: Single-Service Host
Geolocation:
- Country: US (Virginia, Ashburn)
- GeoConsensus: True (1 source)
- Note: RTT validation flagged implausible (24ms observed vs 126.2ms minimum for 6,312km distance). This discrepancy suggests potential geolocation data manipulation or routing anomaly.
DNS & Hostname Resolution:
- PTR Record: sardine319.ahrefs.net
- Forward Resolution: sardine319.ahrefs.net (confirmed)
- Associated Domains: ahrefs.net
- Forward Resolution Count: 1
Open Services:
- Port 22 (TCP/SSH): OpenSSH_9.2p1 Debian-2+deb12u10
---
## Threat Assessment
Risk Indicators:
- Risk Score: 25 (Low Risk)
- Abuse Confidence Score: Null
- Known Attacker: False
- Spam Source: False
- Tor Exit Node: False
- Blacklist Count: 0
- Pulsedive Risk: Null
- Known Campaigns: None
Control Plane:
- Origin ASN: 140577
- BGP Prefix: 202.8.40.0/23
- Route Stability: False (route changes in 30d: 0)
- DNSSEC Valid: True
- DNSBL Listed: 1 of 8 lists (Operator Score: 0.087 - Minimal)
---
## Historical Observations
Total Observations: 19 signals across time
- Most Recent: 2026-06-26 13:35:08 UTC
- Previous Signal: 2026-06-06 07:35:21 UTC
- Threat Persistence Days: 0
- Ownership Changes: 0
Signal Trends: No significant threat escalation detected. IP maintained consistent low-risk profile throughout observation period.
---
## Network Neighborhood Analysis (202.8.41.0/24)
Subnet Classification: mostly_clean
- Abuse Density: 0.1685
- Total Siblings: 89
- Active Siblings: 13
- Threat Siblings: 15
- Inherited Risk: 6
Risk Distribution Across Subnet:
- High Risk: 0
- Medium Risk: 6
- Low Risk: 94
Notable Neighbors:
- 202.8.41.0: Risk 0, Authority 60
- 202.8.41.5: Risk 0, Authority 50
- 202.8.41.7: Risk 25, Authority 60
- 202.8.41.8: Risk 25, Authority 60
- 202.8.41.9: Risk 25, Authority 60
---
## Relationship Graph
DNS Associations: 21 relationships mapped to sardine319.ahrefs.net
Network Associations: 21 relationships mapped to AHREFS-CRAWLER-A-USA network
All relationships indicate standard operational infrastructure with no suspicious cross-contamination or anomalous associations.
---
## Security Actions & Recommendations
Recommended Actions: None
Rationale: Risk score remains low (25) with no active threat indicators, malicious campaigns, or significant blacklist presence. The IP serves legitimate crawler infrastructure purposes for Ahrefs.
---
## Intelligence Narrative
IP 202.8.41.63 represents Ahrefs' crawler infrastructure operating within the 202.8.40.0/23 block. The address functions as a dedicated SSH host (sardine319.ahrefs.net) with minimal exposure to malicious activity. Historical data indicates stable, persistent benign behavior over 19 observation windows.
Key Findings:
1. Legitimate Crawler Infrastructure: Part of Ahrefs' established web crawler network
2. Low Threat Profile: Risk score of 25 with no known attack campaigns
3. Subnet Context: 202.8.41.0/24 shows 94% low-risk classification (94 of 100 neighbors)
4. Geographic Anomaly: RTT validation suggests potential geolocation inconsistency
5. Reputation Stability: No ownership changes or threat persistence detected
SOC Analyst Guidance: Treat as low-priority monitoring. No immediate blocking recommended. The IP demonstrates operational characteristics of a legitimate web crawler rather than a threat actor. Maintain standard logging and monitor for any risk score escalation or new threat indicators.
---
*Report generated from IPDebrief intelligence platform data. All findings based on observed signals and network analysis.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Ahrefs Pte Ltd administrator |
| ASN | AS140577 |
| Network Name | AHREFS-CRAWLER-A-USA |
| CIDR Block | 202.8.40.0/23 |
| RIR | APNIC |
| Country | US |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | sardine319.ahrefs.net |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | sardine319.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.2p1 Debian-2+deb12u10 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 21% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-11 21:44:08 UTC |
| Last Seen | 2026-06-26 13:34:48 UTC |
| Profile Built | 2026-06-26 13:49:35 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 25 |
Full dossier details are available via our API.