# Threat Intelligence Briefing: 92.222.104.200
## Executive Summary
IP 92.222.104.200 is a moderate-risk infrastructure endpoint hosted on OVH cloud infrastructure in Paris, France. While the IP shows no direct threat indicators, it resides within subnet 92.222.104.0/24 exhibiting extremely high abuse density (0.9062). The address resolves to Ahrefs.net domain infrastructure but displays no active services or port exposure.
## Ownership and Infrastructure
- Organization: Ahrefs Pte Ltd Dmytro
- ASN: 16276 (OVH SAS)
- Location: Paris, Île-de-France, France
- Infrastructure Type: CloudCompute (OVH)
- Classification: High-abuse subnet environment
## Technical Profile
- Risk Score: 40/100 (Moderate Risk)
- DNS Resolution: proxy-fr006-san200.ahrefs.net
- Domain: ahrefs.net
- Open Ports: None detected
- Active Services: None
- TLS Certificate: None
- HTTP Banner: None
## Threat Indicators
- Abuse Confidence Score: Not applicable
- Blacklist Status: 0 blacklist entries
- Known Attacker: False
- Tor Exit Node: False
- Spam Source: False
- Active Campaigns: None detected
- Threat Persistence: 0 days observed
## Subnet Context Analysis
The IP resides in subnet 92.222.104.0/24 with concerning characteristics:
- Abuse Density: 0.9062 (Critical - near maximum risk)
- Classification: high_abuse
- Inherited Risk: 36
- Total Siblings: 32
- Active Siblings: 28
- Threat Siblings: 29
All 31 analyzed neighbor IPs in the subnet carry medium-risk scores (40-50), indicating systemic abuse activity across the /24 block.
## Observation History
Analysis of 20 signal observations from June 14, 2026 reveals:
- Consistent geolocation to France (500km accuracy radius)
- Subnet abuse classification maintained as high_abuse
- Operator score: 0.2174 (Minimal threat operator profile)
- No escalation in threat indicators over observation period
- Route stability flagged as false
## Intelligence Assessment
This IP represents cloud infrastructure for Ahrefs, a legitimate SEO analytics platform. The moderate risk score reflects the high-abuse density of its hosting subnet rather than intrinsic malicious activity. The lack of open ports and no direct threat indicators suggests the endpoint is properly firewalled.
## Recommended Actions
- Monitoring: Maintain surveillance due to subnet-level abuse density
- Blocking: Not recommended for this specific IP; consider subnet-level policy review
- Investigation: Review associated domains (ahrefs.net) for potential phishing or credential harvesting campaigns
- Rule Generation: No immediate blocking rules recommended; monitor for service activation
## Confidence Level: High
Data sufficiency: 6/6 dimensions covered
Observation count: 1 threat observation, 19 non-threat observations
Geolocation confidence: Moderate (500km accuracy)
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | proxy-fr006-san200.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-fr006-san200.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 21% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:42 UTC |
| Last Seen | 2026-06-27 09:36:59 UTC |
| Profile Built | 2026-06-28 03:43:26 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 24 |
Full dossier details are available via our API.